HP printers vulnerable
Posted by: Timothy Weaver on 08/08/2013 03:34 PM
[
Comments
]
Hackers have found a way to lift administrative passwords from some HP printers. HP has released patches for the affected LaserJet Pro printers to defend against the vulnerability (CVE-2013-4807), which was discovered by Michał Sajdak of Securitum.pl. Sajdak discovered it was possible to extract plaintext versions of users' passwords via hidden URLs hardcoded into the printers’ firmware. A hex representation of the admin password is stored in a plaintext URL, though it looks encrypted to a casual observer.
HP has released firmware updates for the following affected printers:
HP LaserJet Pro P1102w,
HP LaserJet Pro P1606dn,
HP LaserJet Pro M1212nf MFP,
HP LaserJet Pro M1213nf MFP,
HP LaserJet Pro M1214nfh MFP,
HP LaserJet Pro M1216nfh MFP,
HP LaserJet Pro M1217nfw MFP,
HP LaserJet Pro M1218nfs MFP and
HP LaserJet Pro CP1025nw.
HP's advisory is here.
HP LaserJet Pro P1102w,
HP LaserJet Pro P1606dn,
HP LaserJet Pro M1212nf MFP,
HP LaserJet Pro M1213nf MFP,
HP LaserJet Pro M1214nfh MFP,
HP LaserJet Pro M1216nfh MFP,
HP LaserJet Pro M1217nfw MFP,
HP LaserJet Pro M1218nfs MFP and
HP LaserJet Pro CP1025nw.
HP's advisory is here.
Comments