SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-0941

The HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders has no management password by default, which makes it easier for remote attackers to obtain access.

HIGH 7.6EPSS 3.02%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (3.02%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders has no management password by default, which makes it easier for remote attackers to obtain access.

CVSS 2.0
7.6 HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
EPSS
3.02% probability · 87th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
hp/8100c digital sender · hp/9100c digital sender · hp/9200c digital sender · hp/9250c digital sender · hp/color laserjet · hp/color laserjet 1500 · hp/color laserjet 2500 · hp/color laserjet 2500l · hp/color laserjet 2500lse · hp/color laserjet 2500n · hp/color laserjet 2500tn · hp/color laserjet 2605dtn · hp/color laserjet 4370mfp · hp/color laserjet 4600 · hp/color laserjet 4600dn · hp/color laserjet 4600dtn · hp/color laserjet 4600hdn · hp/color laserjet 4650 · hp/color laserjet 4700 · hp/color laserjet 4730 mfp · +40 more
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.