5.1

CVE-2009-0940

Exploit

Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intranet connectivity of arbitrary users for requests that (1) print documents via unknown vectors, (2) modify the network configuration via a NetIPChange request to hp/device/config_result_YesNo.html/config, or (3) change the password via the Password and ConfirmPassword parameters to hp/device/set_config_password.html/config.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hp8100c Digital Sender Version-
Hp9100c Digital Sender Version-
Hp9200c Digital Sender Version-
Hp9250c Digital Sender Version-
HpColor Laserjet 4370mfp Version20081211_46.211.2
HpColor Laserjet 9500mfp Version20070719_05.011.2
HpColor Mfp Cm8050 Version- Update- Editionedgeline
HpColor Mfp Cm8060 Version- Update- Editionedgeline
HpLaserjet 2410 Version20070410_08.112.3
HpLaserjet 2420 Version20070410_08.112.3
HpLaserjet 2430 Version20070410_08.112.3
HpLaserjet 4250 Version20080319_08.015.0
HpLaserjet 4345mfp Version20081211_09.131.1
HpLaserjet 4350 Version20080319_08.015.0
HpLaserjet 5000 Versionr.25.15
HpLaserjet 5000 Versionr.25.47
HpLaserjet 5100 Versionv.29.12
HpLaserjet 9040 Version20080204_08.110.0
HpLaserjet 9040mfp Version20080204_08.110.0
HpLaserjet 9050 Version20080204_08.110.0
HpLaserjet 9050mfp Version20080204_08.110.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.84% 0.725
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.