HIGH🇵🇱 Wersja polska

CVE-2010-4107

CVSS 7.8v2.0pub. 2010-11-17upd. 2026-04-29

The default configuration of the PJL Access value in the File System External Access settings on HP LaserJet MFP printers, Color LaserJet MFP printers, and LaserJet 4100, 4200, 4300, 5100, 8150, and 9000 printers enables PJL commands that use the device's filesystem, which allows remote attackers to read arbitrary files via a command inside a print job, as demonstrated by a directory traversal attack.

CVSS Vector
AV:N/AC:L/Au:N/C:C/I:N/A:N
  • HP 9000

    HW
    Hp
    all versions
  • HP Color Laserjet Mfp

    HW
    Hp
    all versions
  • HP Laserjet 4100

    HW
    Hp
    all versions
  • HP Laserjet 4200

    HW
    Hp
    all versions
  • HP Laserjet 4300

    HW
    Hp
    all versions
  • HP Laserjet 5100

    HW
    Hp
    all versions
  • HP Laserjet 8150

    HW
    Hp
    all versions
  • HP Laserjet Mfp

    HW
    Hp
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2009-0941HIGH7.6same product

The HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders has no manage...

CVE-2006-6742HIGH7.8same product

Multiple buffer overflows in FTP Print Server 2.4 and 2.4.5 in HP LaserJet 5000 Series printers with firmware ...

CVE-2002-1796HIGH7.8same product

ChaiVM EZloader for HP color LaserJet 4500 and 4550 and HP LaserJet 4100 and 8150 does not properly verify JAR...

CVE-1999-1163HIGH7.5same product

Vulnerability in HP Series 800 S/X/V Class servers allows remote attackers to gain access to the S/X/V Class c...

CVE-2000-0005HIGH7.2same product

HP-UX aserver program allows local users to gain privileges via a symlink attack.