CVE-2010-4107
The default configuration of the PJL Access value in the File System External Access settings on HP LaserJet MFP printers, Color LaserJet MFP printers, and LaserJet 4100, 4200, 4300, 5100, 8150, and 9000 printers enables PJL commands that use the device's filesystem, which allows remote attackers to read arbitrary files via a command inside a print job, as demonstrated by a directory traversal attack.
Published:Nov 17, 2010
Last Modified:Apr 11, 2025
EPS:Nov 17, 2010
EPSS Score:0.29972
CVSS Score:7.8
Affected Products
Vendor
Product
Action
Vendor
Hp
Product
9000
Hp
9000
Vendor
Hp
Product
Color Laserjet Mfp
Hp
Color Laserjet Mfp
Vendor
Hp
Product
Laserjet 4100
Hp
Laserjet 4100
Vendor
Hp
Product
Laserjet 4200
Hp
Laserjet 4200
Vendor
Hp
Product
Laserjet 4300
Hp
Laserjet 4300
Vendor
Hp
Product
Laserjet 5100
Hp
Laserjet 5100
Vendor
Hp
Product
Laserjet 8150
Hp
Laserjet 8150
Vendor
Hp
Product
Laserjet Mfp
Hp
Laserjet Mfp
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
