Mission and Overview
NVD is the U.S. government repository of standards based vulnerability management data. This data enables automation of vulnerability management, security measurement, and compliance (e.g. FISMA).
Resource Status
NVD contains:
CVE Vulnerabilities
38497
Checklists
128
US-CERT Alerts
179
US-CERT Vuln Notes
2345
OVAL Queries
2517
CPE Names
17819

Last updated: Sun Aug 30 21:29:38 EDT 2009

CVE Publication rate: 16.77

Email List

NVD provides four mailing lists to the public. For information and subscription instructions please visit NVD Mailing Lists

Workload Index

Vulnerability Workload Index: 9.73

About Us
NVD is a product of the NIST Computer Security Division and is sponsored by the Department of Homeland Security's National Cyber Security Division. It supports the U.S. government multi-agency (OSD, DHS, NSA, DISA, and NIST) Information Security Automation Program. It is the U.S. government content repository for the Security Content Automation Protocol (SCAP).

National Cyber-Alert System

Vulnerability Summary for CVE-2009-0940

Original release date:03/18/2009
Last revised:04/02/2009
Source: US-CERT/NIST

Overview

Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intranet connectivity of arbitrary users for requests that (1) print documents via unknown vectors, (2) modify the network configuration via a NetIPChange request to hp/device/config_result_YesNo.html/config, or (3) change the password via the Password and ConfirmPassword parameters to hp/device/set_config_password.html/config.

Impact

CVSS Severity (version 2.0):
CVSS v2 Base Score:5.1 (MEDIUM) (AV:N/AC:H/Au:N/C:P/I:P/A:P) (legend)
Impact Subscore: 6.4
Exploitability Subscore: 4.9
CVSS Version 2 Metrics:
Access Vector: Network exploitable; Victim must voluntarily interact with attack mechanism
Access Complexity: High
Authentication: Not required to exploit
Impact Type:Allows unauthorized disclosure of information; Allows unauthorized modification; Allows disruption of service

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.

External Source: VUPEN
Name: ADV-2009-0754
External Source: BID
Name: 34143
External Source: BUGTRAQ
Name: 20090316 HP Laserjet multiple models web management CSRF vulnerability & insecure default configuration
External Source: MISC
Name: http://www.louhinetworks.fi/advisory/HP_20090317.txt
External Source: OSVDB
Name: 52849
External Source: OSVDB
Name: 52848
External Source: OSVDB
Name: 52847
External Source: HP
Name: HPSN-2009-001
Type: Advisory

Vulnerable software and versions

Nav control imageConfiguration 1
spacerNav control imageOR
spacerspacerNav control image* cpe:/h:hp:color_laserjet:2500
spacerspacerNav control image* cpe:/h:hp:color_laserjet:2500lse
spacerspacerNav control image* cpe:/h:hp:color_laserjet_1500
spacerspacerNav control image* cpe:/h:hp:color_laserjet:2500l
spacerspacerNav control image* cpe:/h:hp:color_laserjet:2500tn
spacerspacerNav control image* cpe:/h:hp:color_laserjet:2500n
spacerspacerNav control image* cpe:/h:hp:color_laserjet:4600_toolbox
spacerspacerNav control image* cpe:/h:hp:color_laserjet:4600
spacerspacerNav control image* cpe:/h:hp:color_laserjet_2500n
spacerspacerNav control image* cpe:/h:hp:laserjet_2300dn
spacerspacerNav control image* cpe:/h:hp:color_laserjet_2500lse
spacerspacerNav control image* cpe:/h:hp:laserjet_2200dtn
spacerspacerNav control image* cpe:/h:hp:color_laserjet_2500l
spacerspacerNav control image* cpe:/h:hp:laserjet
spacerspacerNav control image* cpe:/h:hp:color_laserjet_2500
spacerspacerNav control image* cpe:/h:hp:color_laserjet_5550
spacerspacerNav control image* cpe:/h:hp:color_laserjet_8500
spacerspacerNav control image* cpe:/h:hp:color_laserjet_8550
spacerspacerNav control image* cpe:/h:hp:color_laserjet
spacerspacerNav control image* cpe:/h:hp:laserjet_2410:20070410_08.112.3
spacerspacerNav control image* cpe:/h:hp:laserjet_2430
spacerspacerNav control image* cpe:/h:hp:laserjet_2420:20070410_08.112.3
spacerspacerNav control image* cpe:/h:hp:laserjet_2430:20070410_08.112.3
spacerspacerNav control image* cpe:/h:hp:color_laserjet_9500mfp:20070719_05.011.2
spacerspacerNav control image* cpe:/h:hp:laserjet_2200
spacerspacerNav control image* cpe:/h:hp:color_laserjet_4370mfp:20081211_46.211.2
spacerspacerNav control image* cpe:/h:hp:color_laserjet_2500tn
spacerspacerNav control image* cpe:/h:hp:color_laserjet_4600
spacerspacerNav control image* cpe:/h:hp:color_laserjet:4600hdn
spacerspacerNav control image* cpe:/h:hp:color_laserjet_9500_mfp
spacerspacerNav control image* cpe:/h:hp:color_laserjet:4650
spacerspacerNav control image* cpe:/h:hp:color_laserjet:4600dn
spacerspacerNav control image* cpe:/h:hp:color_laserjet_4700
spacerspacerNav control image* cpe:/h:hp:color_laserjet:4600dtn
spacerspacerNav control image* cpe:/h:hp:color_laserjet_4650
spacerspacerNav control image* cpe:/h:hp:color_laserjet_9500
spacerspacerNav control image* cpe:/h:hp:color_laserjet_4730_mfp
spacerspacerNav control image* cpe:/h:hp:color_laserjet:5500
spacerspacerNav control image* cpe:/h:hp:color_laserjet:5550
spacerspacerNav control image* cpe:/h:hp:laserjet_4
spacerspacerNav control image* cpe:/h:hp:laserjet_4000
spacerspacerNav control image* cpe:/h:hp:laserjet_2600n
spacerspacerNav control image* cpe:/h:hp:laserjet_2600c
spacerspacerNav control image* cpe:/h:hp:laserjet_2500c
spacerspacerNav control image* cpe:/h:hp:laserjet_4200ln
spacerspacerNav control image* cpe:/h:hp:laserjet_4100mfp
spacerspacerNav control image* cpe:/h:hp:laserjet_9000mfp
spacerspacerNav control image* cpe:/h:hp:laserjet_4345_mfp
spacerspacerNav control image* cpe:/h:hp:laserjet_4m_plus
spacerspacerNav control image* cpe:/h:hp:laserjet_5
spacerspacerNav control image* cpe:/h:hp:laserjet_5000_printer
spacerspacerNav control image* cpe:/h:hp:laserjet_5100
spacerspacerNav control image* cpe:/h:hp:laserjet_5m
spacerspacerNav control image* cpe:/h:hp:laserjet_2500
spacerspacerNav control image* cpe:/h:hp:laserjet_4250:20080319_08.015.0
spacerspacerNav control image* cpe:/h:hp:laserjet_4300
spacerspacerNav control image* cpe:/h:hp:laserjet_4200
spacerspacerNav control image* cpe:/h:hp:laserjet_4350:20080319_08.015.0
spacerspacerNav control image* cpe:/h:hp:laserjet_5000:r.25.15
spacerspacerNav control image* cpe:/h:hp:laserjet_9000_mfp
spacerspacerNav control image* cpe:/h:hp:laserjet_9000
spacerspacerNav control image* cpe:/h:hp:laserjet_3000
spacerspacerNav control image* cpe:/h:hp:laserjet_4100_mfp
spacerspacerNav control image* cpe:/h:hp:laserjet_9040mfp
spacerspacerNav control image* cpe:/h:hp:laserjet_3700
spacerspacerNav control image* cpe:/h:hp:laserjet_9040:20080204_08.110.0
spacerspacerNav control image* cpe:/h:hp:laserjet_9040_mpf
spacerspacerNav control image* cpe:/h:hp:laserjet_4345mfp:20081211_09.131.1
spacerspacerNav control image* cpe:/h:hp:laserjet_5000:r.25.47
spacerspacerNav control image* cpe:/h:hp:laserjet_5100:v.29.12
spacerspacerNav control image* cpe:/h:hp:laserjet_5000
spacerspacerNav control image* cpe:/h:hp:laserjet_4650dn
spacerspacerNav control image* cpe:/h:hp:laserjet_5100dtn
spacerspacerNav control image* cpe:/h:hp:laserjet_4050
spacerspacerNav control image* cpe:/h:hp:laserjet_4000n
spacerspacerNav control image* cpe:/h:hp:laserjet_4350dtn
spacerspacerNav control image* cpe:/h:hp:laserjet_4200dnt_network_printer
spacerspacerNav control image* cpe:/h:hp:laserjet_8150dn
spacerspacerNav control image* cpe:/h:hp:laserjet_9040_mfp
spacerspacerNav control image* cpe:/h:hp:laserjet_9500mfp
spacerspacerNav control image* cpe:/h:hp:laserjet_9050:20080204_08.110.0
spacerspacerNav control image* cpe:/h:hp:laserjet_9050mfp:20080204_08.110.0
spacerspacerNav control image* cpe:/h:hp:laserjet_9050mfp
spacerspacerNav control image* cpe:/h:hp:laserjet_9500
spacerspacerNav control image* cpe:/h:hp:laserjet_9065
spacerspacerNav control image* cpe:/h:hp:laserjet_9500_mpf
spacerspacerNav control image* cpe:/h:hp:laserjet_9040mfp:20080204_08.110.0
spacerspacerNav control image* cpe:/h:hp:laserjet_9050
spacerspacerNav control image* cpe:/h:hp:laserjet_9055
spacerspacerNav control image* cpe:/h:hp:laserjet_9050_mpf
spacerspacerNav control image* cpe:/h:hp:laserjet_m5035_mfp
spacerspacerNav control image* cpe:/h:hp:laserjet_m5025_mfp
spacerspacerNav control image* cpe:/h:hp:laserjet_m3035_mfp
spacerspacerNav control image* cpe:/h:hp:laserjet_m3027_mfp
spacerspacerNav control image* cpe:/h:hp:laserjet_m4345_mfp
spacerspacerNav control image* cpe:/h:hp:laserjet_9050_mfp
spacerspacerNav control image* cpe:/h:hp:digital_senders
spacerspacerNav control image* cpe:/h:hp:edgeline_printers
spacerspacerNav control image* cpe:/h:hp:laserjet_m1522n_mfp
spacerspacerNav control image* cpe:/h:hp:color_laserjet_2605dtn
spacerspacerNav control image* cpe:/h:hp:color_mfp_cm8060:-:-:edgeline
spacerspacerNav control image* cpe:/h:hp:color_mfp_cm8050:-:-:edgeline
spacerspacerNav control image* cpe:/h:hp:9200c_digital_sender:-
spacerspacerNav control image* cpe:/h:hp:8100c_digital_sender:-
spacerspacerNav control image* cpe:/h:hp:9100c_digital_sender:-
spacerspacerNav control image* cpe:/h:hp:9250c_digital_sender:-
spacerspacerNav control image* cpe:/h:hp:laserjet:5%2Fm%2Fn
spacerspacerNav control image* cpe:/h:hp:laserjet:5p%2Fmp
spacerspacerNav control image* cpe:/h:hp:laserjet:5l
spacerspacerNav control image* cpe:/h:hp:laserjet:5si
spacerspacerNav control image* cpe:/h:hp:laserjet:4v%2Fmv
spacerspacerNav control image* cpe:/h:hp:laserjet:4_plus%2Fm_plus
spacerspacerNav control image* cpe:/h:hp:laserjet:4%2F4m
spacerspacerNav control image* cpe:/h:hp:laserjet:4l%2Fml
spacerspacerNav control image* cpe:/h:hp:laserjet:4si
spacerspacerNav control image* cpe:/h:hp:laserjet:4p%2Fmp
spacerspacerNav control image* cpe:/h:hp:laserjet:3
spacerspacerNav control image* cpe:/h:hp:laserjet:3d
spacerspacerNav control image* cpe:/h:hp:laserjet:3p
spacerspacerNav control image* cpe:/h:hp:laserjet:3si
spacerspacerNav control image* cpe:/h:hp:laserjet:series2
spacerspacerNav control image* cpe:/h:hp:laserjet:2p
spacerspacerNav control image* cpe:/h:hp:laserjet:2p_plus
spacerspacerNav control image* cpe:/h:hp:laserjet:2d
spacerspacerNav control image* cpe:/h:hp:laserjet:500_plus
spacerspacerNav control image* cpe:/h:hp:laserjet:p1005
spacerspacerNav control image* cpe:/h:hp:laserjet:p1006
spacerspacerNav control image* cpe:/h:hp:laserjet:p1007
spacerspacerNav control image* cpe:/h:hp:laserjet:p1008
spacerspacerNav control image* cpe:/h:hp:laserjet:p1009
spacerspacerNav control image* cpe:/h:hp:laserjet:p1505
spacerspacerNav control image* cpe:/h:hp:laserjet:p1505n
spacerspacerNav control image* cpe:/h:hp:laserjet:p2010
spacerspacerNav control image* cpe:/h:hp:laserjet:p2015
spacerspacerNav control image* cpe:/h:hp:laserjet:p2030
spacerspacerNav control image* cpe:/h:hp:laserjet:p2050
spacerspacerNav control image* cpe:/h:hp:laserjet:p3005
spacerspacerNav control image* cpe:/h:hp:laserjet:p4014
spacerspacerNav control image* cpe:/h:hp:laserjet:p4015
spacerspacerNav control image* cpe:/h:hp:laserjet:p4510
spacerspacerNav control image* cpe:/h:hp:laserjet:p4500
spacerspacerNav control image* cpe:/h:hp:laserjet:p4010
spacerspacerNav control image* cpe:/h:hp:laserjet:p3000
spacerspacerNav control image* cpe:/h:hp:laserjet:p2000
spacerspacerNav control image* cpe:/h:hp:laserjet:p1500
spacerspacerNav control image* cpe:/h:hp:laserjet:p1000
spacerspacerNav control image* cpe:/h:hp:laserjet:2
spacerspacerNav control image* cpe:/h:hp:laserjet:1000
spacerspacerNav control image* cpe:/h:hp:laserjet:1005
spacerspacerNav control image* cpe:/h:hp:laserjet:1010
spacerspacerNav control image* cpe:/h:hp:laserjet:1012
spacerspacerNav control image* cpe:/h:hp:laserjet:1015
spacerspacerNav control image* cpe:/h:hp:laserjet:1018
spacerspacerNav control image* cpe:/h:hp:laserjet:1018s
spacerspacerNav control image* cpe:/h:hp:laserjet:1020
spacerspacerNav control image* cpe:/h:hp:laserjet:1022
spacerspacerNav control image* cpe:/h:hp:laserjet:1022n
spacerspacerNav control image* cpe:/h:hp:laserjet:1022nw
spacerspacerNav control image* cpe:/h:hp:laserjet:1020_plus
spacerspacerNav control image* cpe:/h:hp:laserjet:1100
spacerspacerNav control image* cpe:/h:hp:laserjet:1150
spacerspacerNav control image* cpe:/h:hp:laserjet:1160
spacerspacerNav control image* cpe:/h:hp:laserjet:1200
spacerspacerNav control image* cpe:/h:hp:laserjet:1300
spacerspacerNav control image* cpe:/h:hp:laserjet:1320
spacerspacerNav control image* cpe:/h:hp:laserjet:2000
spacerspacerNav control image* cpe:/h:hp:laserjet:2100
spacerspacerNav control image* cpe:/h:hp:laserjet:2200
spacerspacerNav control image* cpe:/h:hp:laserjet:2300
spacerspacerNav control image* cpe:/h:hp:laserjet:2400
spacerspacerNav control image* cpe:/h:hp:laserjet:4000
spacerspacerNav control image* cpe:/h:hp:laserjet:4100
spacerspacerNav control image* cpe:/h:hp:laserjet:4200
spacerspacerNav control image* cpe:/h:hp:laserjet:4240
spacerspacerNav control image* cpe:/h:hp:laserjet:4240n
spacerspacerNav control image* cpe:/h:hp:laserjet:4250
spacerspacerNav control image* cpe:/h:hp:laserjet:4300
spacerspacerNav control image* cpe:/h:hp:laserjet:4350
spacerspacerNav control image* cpe:/h:hp:laserjet:4050
spacerspacerNav control image* cpe:/h:hp:laserjet:5000
spacerspacerNav control image* cpe:/h:hp:laserjet:5100
spacerspacerNav control image* cpe:/h:hp:laserjet:5200
spacerspacerNav control image* cpe:/h:hp:laserjet:8000
spacerspacerNav control image* cpe:/h:hp:laserjet:8100
spacerspacerNav control image* cpe:/h:hp:laserjet:8150
spacerspacerNav control image* cpe:/h:hp:laserjet:9000
spacerspacerNav control image* cpe:/h:hp:laserjet:9040
spacerspacerNav control image* cpe:/h:hp:laserjet:9050
* Denotes Vulnerable Software

Technical Details

Vulnerability Type (View All)
  • Cross-Site Request Forgery (CSRF) (CWE-352)