7.8
CVSSv2

CVE-2013-4807

Published: 05/08/2013 Updated: 29/08/2017
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:C/A:N

Vulnerability Summary

Unspecified vulnerability on the HP LaserJet Pro P1102w, P1606dn, M1212nf MFP, M1213nf MFP, M1214nfh MFP, M1216nfh MFP, M1217nfw MFP, M1218nfs MFP, and CP1025nw with firmware prior to 2013-07-26 20130703 allows remote malicious users to modify data via unknown vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

hp laserjet_pro_cp1025nw_firmware 20130703

hp laserjet_pro_m1214nfh_mfp_firmware 20130703

hp laserjet_pro_p1606dn_firmware 20130212

hp laserjet_pro_m1216nfh_multifunction_printer_firmware 20130703

hp laserjet_pro_m1213nf_mfp_firmware 20130703

hp laserjet_pro_m1212nf_mfp_firmware 20130703

hp laserjet_pro_m1217nfw_multifunction_printer_firmware 20130703

hp laserjet_pro_p1102w_firmware 20130703

hp hotspot_laserjet_pro_m1218nfs_mfp_firmware 20130703

Vendor Advisories

A potential security vulnerability has been identified with certain HP LaserJet Pro printers The vulnerability could be exploited remotely to gain unauthorized access to data ...

Recent Articles

HP plugs password-leaking printer flaw
The Register • John Leyden • 08 Aug 2013

Bad news: Most office bods won't patch it. Good news: Most office bods won't find password

Security flaws in a range of HP printers create a way for hackers to lift administrator's passwords and other potentially sensitive information from vulnerable devices, infosec experts have warned. HP has released patches for the affected LaserJet Pro printers to defend against the vulnerability (CVE-2013-4807), which was discovered by Michał Sajdak of Securitum.pl. Sajdak discovered it was possible to extract plaintext versions of users' passwords via hidden URLs hardcoded into the printers’...