SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-0940

Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intranet connectivity of arbitrary users for requests…

MEDIUM 5.1EPSS 1.08%

Does this matter?

Lower severity and a low EPSS score (1.08%). Track it; it rarely justifies an emergency change on its own.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intranet connectivity of arbitrary users for requests that (1) print documents via unknown vectors, (2) modify the network configuration via a NetIPChange request to hp/device/config_result_YesNo.html/config, or (3) change the password via the Password and ConfirmPassword parameters to hp/device/set_config_password.html/config.

CVSS 2.0
5.1 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
EPSS
1.08% probability · 63th percentile
CISA KEV
Not listed
Weakness
CWE-352
Affected
hp/8100c digital sender · hp/9100c digital sender · hp/9200c digital sender · hp/9250c digital sender · hp/color laserjet · hp/color laserjet 1500 · hp/color laserjet 2500 · hp/color laserjet 2500l · hp/color laserjet 2500lse · hp/color laserjet 2500n · hp/color laserjet 2500tn · hp/color laserjet 2605dtn · hp/color laserjet 4370mfp · hp/color laserjet 4600 · hp/color laserjet 4600dn · hp/color laserjet 4600dtn · hp/color laserjet 4600hdn · hp/color laserjet 4650 · hp/color laserjet 4700 · hp/color laserjet 4730 mfp · +40 more
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.