The default configuration of the PJL Access value in the File System External Access settings on HP LaserJet MFP printers, Color LaserJet MFP printers, and LaserJet 4100, 4200, 4300, 5100, 8150, and 9000 printers enables PJL commands that use the device's filesystem, which allows remote attackers to read arbitrary files via a command inside a print job, as demonstrated by a directory traversal attack.
AV:N/AC:L/Au:N/C:C/I:N/A:NHP 9000
HWHpall versionsHP Color Laserjet Mfp
HWHpall versionsHP Laserjet 4100
HWHpall versionsHP Laserjet 4200
HWHpall versionsHP Laserjet 4300
HWHpall versionsHP Laserjet 5100
HWHpall versionsHP Laserjet 8150
HWHpall versionsHP Laserjet Mfp
HWHpall versions
Related vulnerabilities
The HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders has no manage...
Multiple buffer overflows in FTP Print Server 2.4 and 2.4.5 in HP LaserJet 5000 Series printers with firmware ...
ChaiVM EZloader for HP color LaserJet 4500 and 4550 and HP LaserJet 4100 and 8150 does not properly verify JAR...
Vulnerability in HP Series 800 S/X/V Class servers allows remote attackers to gain access to the S/X/V Class c...
HP-UX aserver program allows local users to gain privileges via a symlink attack.