CVE-2009-0940

CVSS V2 Medium 5.1 CVSS V3 None
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intranet connectivity of arbitrary users for requests that (1) print documents via unknown vectors, (2) modify the network configuration via a NetIPChange request to hp/device/config_result_YesNo.html/config, or (3) change the password via the Password and ConfirmPassword parameters to hp/device/set_config_password.html/config.
Overview
  • CVE ID
  • CVE-2009-0940
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Modified
  • Published Version
  • 2009-03-18T21:00:00
  • Last Modified Date
  • 2018-10-10T19:32:25
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:h:hp:8100c_digital_sender:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:9100c_digital_sender:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:9200c_digital_sender:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:9250c_digital_sender:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:color_laserjet:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:color_laserjet_1500:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:color_laserjet_2500:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:color_laserjet_2500l:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:color_laserjet_2500lse:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:color_laserjet_2500n:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:color_laserjet_2500tn:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:color_laserjet_2605dtn:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:color_laserjet_4370mfp:20081211_46.211.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:color_laserjet_4600:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:color_laserjet_4600dn:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:color_laserjet_4600dtn:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:color_laserjet_4600hdn:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:color_laserjet_4650:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:color_laserjet_4700:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:color_laserjet_4730_mfp:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:color_laserjet_5500:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:color_laserjet_5550:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:color_laserjet_8500:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:color_laserjet_8550:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:color_laserjet_9500:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:color_laserjet_9500_mfp:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:color_laserjet_9500mfp:20070719_05.011.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:color_mfp_cm8050:-:-:edgeline:*:*:*:*:* 1 OR
cpe:2.3:h:hp:color_mfp_cm8060:-:-:edgeline:*:*:*:*:* 1 OR
cpe:2.3:h:hp:digital_senders:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:edgeline_printers:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_1000:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_1005:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_1010:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_1012:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_1015:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_1018:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_1018s:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_1020:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_1020_plus:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_1022:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_1022n:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_1022nw:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_1100:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_1150:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_1160:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_1200:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_1300:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_1320:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_2:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_2000:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_2100:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_2200:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_2200dtn:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_2300:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_2300dn:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_2400:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_2410:20070410_08.112.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_2420:20070410_08.112.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_2430:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_2430:20070410_08.112.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_2500:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_2500c:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_2600c:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_2600n:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_3000:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_3700:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4\/4m:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4_plus\/m_plus:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4000:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4000n:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4050:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4100:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4100_mfp:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4100mfp:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4200:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4200dtn:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4200ln:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4240:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4240n:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4250:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4250:20080319_08.015.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4300:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4345_mfp:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4345mfp:20081211_09.131.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4350:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4350:20080319_08.015.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4350dtn:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4650dn:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4l\/ml:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4m_plus:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4p\/mp:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4si:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_4v\/mv:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_5:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_5\/m\/n:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_500_plus:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_5000:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_5000:r.25.15:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_5000:r.25.47:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_5100:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_5100:v.29.12:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_5100dtn:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_5200:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_5l:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_5m:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_5p\/mp:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_5si:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_8000:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_8100:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_8150:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_8150dn:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_9000:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_9000_mfp:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_9000mfp:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_9040:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_9040:20080204_08.110.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_9040mfp:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_9040mfp:20080204_08.110.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_9050:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_9050:20080204_08.110.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_9050_mfp:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_9050mfp:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_9050mfp:20080204_08.110.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_9055:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_9065:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_9500:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_9500mfp:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_ii:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_iid:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_iii:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_iiid:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_iiip:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_iiisi:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_iip:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_iip_plus:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_m1522n_mfp:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_m3027_mfp:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_m3035_mfp:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_m4345_mfp:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_m5025_mfp:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_m5035_mfp:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_p1000:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_p1005:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_p1006:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_p1007:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_p1008:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_p1009:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_p1500:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_p1505:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_p1505n:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_p2000:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_p2010:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_p2015:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_p2030:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_p2050:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_p3000:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_p3005:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_p4010:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_p4014:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_p4015:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_p4500:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:hp:laserjet_p4510:*:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:H/Au:N/C:P/I:P/A:P
  • Access Vector
  • NETWORK
  • Access Compatibility
  • HIGH
  • Authentication
  • NONE
  • Confidentiality Impact
  • PARTIAL
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • PARTIAL
  • Base Score
  • 5.1
  • Severity
  • MEDIUM
  • Exploitability Score
  • 4.9
  • Impact Score
  • 6.4
History
Created Old Value New Value Data Type Notes
2022-05-10 18:33:15 Added to TrackCVE