Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2011-4161


The default configuration of the HP CM8060 Color MFP with Edgeline; Color LaserJet 3xxx, 4xxx, 5550, 9500, CMxxxx, CPxxxx, and Enterprise CPxxxx; Digital Sender 9200c and 9250c; LaserJet 4xxx, 5200, 90xx, Mxxxx, and Pxxxx; and LaserJet Enterprise 500 color M551, 600, M4555 MFP, and P3015 enables the Remote Firmware Update (RFU) setting, which allows remote attackers to execute arbitrary code by using a session on TCP port 9100 to upload a crafted firmware update.


Security Impact Summary

CVE-2011-4161 is a security vulnerability that . Impacting 41 products from hp, from hp, from hp and 38 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Documented in 2011, this vulnerability occurred amid the cloud computing expansion era, where traditional network perimeter security models were being reevaluated. Organizations were transitioning from isolated infrastructure to interconnected systems, creating new attack surfaces that vulnerabilities like this could exploit.


Published

2011-12-01T21:55:00.707

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 10.0 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Hardware hp color_laserjet_3000 * Yes
Hardware hp color_laserjet_3800 * Yes
Hardware hp color_laserjet_4700 * Yes
Hardware hp color_laserjet_4730 mfp Yes
Hardware hp color_laserjet_4730_mfp * Yes
Hardware hp color_laserjet_5550 * Yes
Hardware hp color_laserjet_9500 * Yes
Hardware hp color_laserjet_cm3530 * Yes
Hardware hp color_laserjet_cm4540 mfp Yes
Hardware hp color_laserjet_cm4730 mfp Yes
Hardware hp color_laserjet_cm6030 * Yes
Hardware hp color_laserjet_cm6040 * Yes
Hardware hp color_laserjet_cp3505 * Yes
Hardware hp color_laserjet_cp3525 * Yes
Hardware hp color_laserjet_cp4005 * Yes
Hardware hp color_laserjet_cp5525 * Yes
Hardware hp color_laserjet_cp6015 * Yes
Hardware hp color_laserjet_enterprise_cp4520 * Yes
Hardware hp color_laserjet_enterprise_cp4525 * Yes
Hardware hp color_mfp_cm8060 - Yes
Hardware hp digital_sender_9200c * Yes
Hardware hp digital_sender_9250c * Yes
Hardware hp laserjet_4240 * Yes
Hardware hp laserjet_4250 * Yes
Hardware hp laserjet_4345_mfp * Yes
Hardware hp laserjet_4350 * Yes
Hardware hp laserjet_5200 * Yes
Hardware hp laserjet_9040 * Yes
Hardware hp laserjet_9050 * Yes
Hardware hp laserjet_enterprise_500_color m551 Yes
Hardware hp laserjet_enterprise_600 m601 Yes
Hardware hp laserjet_enterprise_600 m602 Yes
Hardware hp laserjet_enterprise_600 m603 Yes
Hardware hp laserjet_enterprise_m4555 mfp Yes
Hardware hp laserjet_enterprise_p3015 * Yes
Hardware hp laserjet_m3035 * Yes
Hardware hp laserjet_m5035 * Yes
Hardware hp laserjet_m9040 * Yes
Hardware hp laserjet_m9050 * Yes
Hardware hp laserjet_p3005 * Yes
Hardware hp laserjet_p4014 * Yes
Hardware hp laserjet_p4015 * Yes
Hardware hp laserjet_p4515 * Yes

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For hp's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.