SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-5221

Directory traversal vulnerability in the PostScript Interpreter, as used on the HP LaserJet 4xxx, 5200, 90xx, M30xx, M4345, M50xx, M90xx, P3005, and P4xxx; LaserJet Enterprise P3015; Color LaserJet 3xxx, 47xx, 5550, 9500, CM60xx, CP35xx, CP4005, and…

MEDIUM 5.0EPSS 3.88%

Does this matter?

Lower severity and a low EPSS score (3.88%). Track it; it rarely justifies an emergency change on its own.

Description

Directory traversal vulnerability in the PostScript Interpreter, as used on the HP LaserJet 4xxx, 5200, 90xx, M30xx, M4345, M50xx, M90xx, P3005, and P4xxx; LaserJet Enterprise P3015; Color LaserJet 3xxx, 47xx, 5550, 9500, CM60xx, CP35xx, CP4005, and CP6015; Color LaserJet Enterprise CP4xxx; and 9250c Digital Sender with model-dependent firmware through 52.x allows remote attackers to read arbitrary files via unknown vectors.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
3.88% probability · 90th percentile
CISA KEV
Not listed
Affected
hp/color laserjet 3000 · hp/color laserjet 3800 · hp/color laserjet 4700 · hp/color laserjet 4730 mfp · hp/color laserjet 5550 · hp/color laserjet 9500 mfp · hp/color laserjet cm6030 mfp · hp/color laserjet cm6040 mfp · hp/color laserjet cp3505 · hp/color laserjet cp3525 · hp/color laserjet cp4005 · hp/color laserjet cp6015 · hp/color laserjet enterprise cp4025 · hp/color laserjet enterprise cp4525 · hp/digital sender 9250c · hp/laserjet 4240 · hp/laserjet 4250 · hp/laserjet 4345 mfp · hp/laserjet 4350 · hp/laserjet 5200l · +17 more
Source
hp-security-alert@hp.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.