← Back

CVE-2009-0940

nvd nist
Published: Mar 18, 2009Modified: Apr 23, 2026

JSON object

Loading...
5.1
Vector
AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploitability: 4.9 / Impact: 6.4
Source: NVD

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intranet connectivity of arbitrary users for requests that (1) print documents via unknown vectors, (2) modify the network configuration via a NetIPChange request to hp/device/config_result_YesNo.html/config, or (3) change the password via the Password and ConfirmPassword parameters to hp/device/set_config_password.html/config.

Affected (164)

Products: Hp: 8100c Digital Sender, 9100c Digital Sender, 9200c Digital Sender, 9250c Digital Sender, Color Laserjet, Color Laserjet 1500, Color Laserjet 2500, Color Laserjet 2500l, Color Laserjet 2500lse, Color Laserjet 2500n, Color Laserjet 2500tn, Color Laserjet 2605dtn, Color Laserjet 4370mfp, Color Laserjet 4600, Color Laserjet 4600dn, Color Laserjet 4600dtn, Color Laserjet 4600hdn, Color Laserjet 4650, Color Laserjet 4700, Color Laserjet 4730 Mfp, Color Laserjet 5500, Color Laserjet 5550, Color Laserjet 8500, Color Laserjet 8550, Color Laserjet 9500, Color Laserjet 9500 Mfp, Color Laserjet 9500mfp, Color Mfp Cm8050, Color Mfp Cm8060, Digital Senders, Edgeline Printers, Laserjet 1000, Laserjet 1005, Laserjet 1010, Laserjet 1012, Laserjet 1015, Laserjet 1018, Laserjet 1018s, Laserjet 1020, Laserjet 1020 Plus, Laserjet 1022, Laserjet 1022n, Laserjet 1022nw, Laserjet 1100, Laserjet 1150, Laserjet 1160, Laserjet 1200, Laserjet 1300, Laserjet 1320, Laserjet 2, Laserjet 2000, Laserjet 2100, Laserjet 2200, Laserjet 2200dtn, Laserjet 2300, Laserjet 2300dn, Laserjet 2400, Laserjet 2410, Laserjet 2420, Laserjet 2430, Laserjet 2500, Laserjet 2500c, Laserjet 2600c, Laserjet 2600n, Laserjet 3000, Laserjet 3700, Laserjet 4, Laserjet 4/4m, Laserjet 4000, Laserjet 4000n, Laserjet 4050, Laserjet 4100, Laserjet 4100 Mfp, Laserjet 4100mfp, Laserjet 4200, Laserjet 4200dtn, Laserjet 4200ln, Laserjet 4240, Laserjet 4240n, Laserjet 4250, Laserjet 4300, Laserjet 4345 Mfp, Laserjet 4345mfp, Laserjet 4350, Laserjet 4350dtn, Laserjet 4650dn, Laserjet 4 Plus/m Plus, Laserjet 4l/ml, Laserjet 4m Plus, Laserjet 4p/mp, Laserjet 4si, Laserjet 4v/mv, Laserjet 5, Laserjet 5/m/n, Laserjet 5000, Laserjet 500 Plus, Laserjet 5100, Laserjet 5100dtn, Laserjet 5200, Laserjet 5l, Laserjet 5m, Laserjet 5p/mp, Laserjet 5si, Laserjet 8000, Laserjet 8100, Laserjet 8150, Laserjet 8150dn, Laserjet 9000, Laserjet 9000 Mfp, Laserjet 9000mfp, Laserjet 9040, Laserjet 9040mfp, Laserjet 9050, Laserjet 9050 Mfp, Laserjet 9050mfp, Laserjet 9055, Laserjet 9065, Laserjet 9500, Laserjet 9500mfp, Laserjet Ii, Laserjet Iid, Laserjet Iii, Laserjet Iiid, Laserjet Iiip, Laserjet Iiisi, Laserjet Iip, Laserjet Iip Plus, Laserjet M1522n Mfp, Laserjet M3027 Mfp, Laserjet M3035 Mfp, Laserjet M4345 Mfp, Laserjet M5025 Mfp, Laserjet M5035 Mfp, Laserjet P1000, Laserjet P1005, Laserjet P1006, Laserjet P1007, Laserjet P1008, Laserjet P1009, Laserjet P1500, Laserjet P1505, Laserjet P1505n, Laserjet P2000, Laserjet P2010, Laserjet P2015, Laserjet P2030, Laserjet P2050, Laserjet P3000, Laserjet P3005, Laserjet P4010, Laserjet P4014, Laserjet P4015, Laserjet P4500, Laserjet P4510
154 products
8100c Digital Sender
9100c Digital Sender
9200c Digital Sender
9250c Digital Sender
Color Laserjet
Color Laserjet 1500
Color Laserjet 2500
Color Laserjet 2500l
Color Laserjet 2500lse
Color Laserjet 2500n
Color Laserjet 2500tn
Color Laserjet 2605dtn
Color Laserjet 4370mfp
Color Laserjet 4600
Color Laserjet 4600dn
Color Laserjet 4600dtn
Color Laserjet 4600hdn
Color Laserjet 4650
Color Laserjet 4700
Color Laserjet 4730 Mfp
Color Laserjet 5500
Color Laserjet 5550
Color Laserjet 8500
Color Laserjet 8550
Color Laserjet 9500
Color Laserjet 9500 Mfp
Color Laserjet 9500mfp
Color Mfp Cm8050
Color Mfp Cm8060
Digital Senders
Edgeline Printers
Laserjet 1000
Laserjet 1005
Laserjet 1010
Laserjet 1012
Laserjet 1015
Laserjet 1018
Laserjet 1018s
Laserjet 1020
Laserjet 1020 Plus
Laserjet 1022
Laserjet 1022n
Laserjet 1022nw
Laserjet 1100
Laserjet 1150
Laserjet 1160
Laserjet 1200
Laserjet 1300
Laserjet 1320
Laserjet 2
Laserjet 2000
Laserjet 2100
Laserjet 2200
Laserjet 2200dtn
Laserjet 2300
Laserjet 2300dn
Laserjet 2400
Laserjet 2410
Laserjet 2420
Laserjet 2430
Laserjet 2500
Laserjet 2500c
Laserjet 2600c
Laserjet 2600n
Laserjet 3000
Laserjet 3700
Laserjet 4
Laserjet 4/4m
Laserjet 4000
Laserjet 4000n
Laserjet 4050
Laserjet 4100
Laserjet 4100 Mfp
Laserjet 4100mfp
Laserjet 4200
Laserjet 4200dtn
Laserjet 4200ln
Laserjet 4240
Laserjet 4240n
Laserjet 4250
Laserjet 4300
Laserjet 4345 Mfp
Laserjet 4345mfp
Laserjet 4350
Laserjet 4350dtn
Laserjet 4650dn
Laserjet 4 Plus/m Plus
Laserjet 4l/ml
Laserjet 4m Plus
Laserjet 4p/mp
Laserjet 4si
Laserjet 4v/mv
Laserjet 5
Laserjet 5/m/n
Laserjet 5000
Laserjet 500 Plus
Laserjet 5100
Laserjet 5100dtn
Laserjet 5200
Laserjet 5l
Laserjet 5m
Laserjet 5p/mp
Laserjet 5si
Laserjet 8000
Laserjet 8100
Laserjet 8150
Laserjet 8150dn
Laserjet 9000
Laserjet 9000 Mfp
Laserjet 9000mfp
Laserjet 9040
Laserjet 9040mfp
Laserjet 9050
Laserjet 9050 Mfp
Laserjet 9050mfp
Laserjet 9055
Laserjet 9065
Laserjet 9500
Laserjet 9500mfp
Laserjet Ii
Laserjet Iid
Laserjet Iii
Laserjet Iiid
Laserjet Iiip
Laserjet Iiisi
Laserjet Iip
Laserjet Iip Plus
Laserjet M1522n Mfp
Laserjet M3027 Mfp
Laserjet M3035 Mfp
Laserjet M4345 Mfp
Laserjet M5025 Mfp
Laserjet M5035 Mfp
Laserjet P1000
Laserjet P1005
Laserjet P1006
Laserjet P1007
Laserjet P1008
Laserjet P1009
Laserjet P1500
Laserjet P1505
Laserjet P1505n
Laserjet P2000
Laserjet P2010
Laserjet P2015
Laserjet P2030
Laserjet P2050
Laserjet P3000
Laserjet P3005
Laserjet P4010
Laserjet P4014
Laserjet P4015
Laserjet P4500
Laserjet P4510
Configuration A
164 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
Version 20081211_46.211.2
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
Version 20070719_05.011.2
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
Version 20070410_08.112.3
Version 20070410_08.112.3
Hp
All versions
Version 20070410_08.112.3
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
Hp
All versions
Version 20080319_08.015.0
All versions
All versions
Version 20081211_09.131.1
Hp
All versions
Version 20080319_08.015.0
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
Hp
All versions
Version r.25.15
Version r.25.47
All versions
Hp
All versions
Version v.29.12
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
Hp
All versions
Version 20080204_08.110.0
Hp
All versions
Version 20080204_08.110.0
Hp
All versions
Version 20080204_08.110.0
All versions
Hp
All versions
Version 20080204_08.110.0
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions

References (16)

Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.