Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2010-4107


The default configuration of the PJL Access value in the File System External Access settings on HP LaserJet MFP printers, Color LaserJet MFP printers, and LaserJet 4100, 4200, 4300, 5100, 8150, and 9000 printers enables PJL commands that use the device's filesystem, which allows remote attackers to read arbitrary files via a command inside a print job, as demonstrated by a directory traversal attack.


Published

2010-11-17T16:00:02.623

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.8 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

6.9

Weaknesses
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Hardware hp 9000 * Yes
Hardware hp color_laserjet_mfp * Yes
Hardware hp laserjet_4100 * Yes
Hardware hp laserjet_4200 * Yes
Hardware hp laserjet_4300 * Yes
Hardware hp laserjet_5100 * Yes
Hardware hp laserjet_8150 * Yes
Hardware hp laserjet_mfp * Yes

References