SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2004-2439

The remote upgrade capability in HP LaserJet 4200 and 4300 printers does not require a password, which allows remote attackers to upgrade firmware.

MEDIUM 5.0EPSS 2.22%

Does this matter?

Lower severity and a low EPSS score (2.22%). Track it; it rarely justifies an emergency change on its own.

Description

The remote upgrade capability in HP LaserJet 4200 and 4300 printers does not require a password, which allows remote attackers to upgrade firmware.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
2.22% probability · 82th percentile
CISA KEV
Not listed
Affected
hp/color laserjet · hp/color laserjet 4600 · hp/laserjet 2500 · hp/laserjet 3000 · hp/laserjet 3700 · hp/laserjet 4100 mfp · hp/laserjet 4200 · hp/laserjet 4300 · hp/laserjet 9000 · hp/laserjet 9000 mfp · hp/laserjet 9040 mpf · hp/laserjet 9050 · hp/laserjet 9050 mpf · hp/laserjet 9055 · hp/laserjet 9065 · hp/laserjet 9500 · hp/laserjet 9500 mpf
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.