HP LaserJet 4200/4300 Printer Arbitrary Firmware Upgrade Vulnerability
BID:11297
Info
HP LaserJet 4200/4300 Printer Arbitrary Firmware Upgrade Vulnerability
| Bugtraq ID: | 11297 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 30 2004 12:00AM |
| Updated: | Sep 30 2004 12:00AM |
| Credit: | Serguei Patchkovskii <[email protected]> reported this vulnerability. |
| Vulnerable: |
HP LaserJet 9500mpf HP LaserJet 9500 0 HP LaserJet 9065 0 HP LaserJet 9055 0 HP LaserJet 9050mpf 0 HP LaserJet 9050 0 HP LaserJet 9040mpf 0 HP LaserJet 9000MFP HP LaserJet 9000 HP LaserJet 4300 HP LaserJet 4200 HP LaserJet 4100MFP HP LaserJet 3700 HP LaserJet 3000 HP LaserJet 2500 HP Color LaserJet 5550 HP Color LaserJet 5500 HP Color LaserJet 4650 HP Color LaserJet 4600 0 |
| Not Vulnerable: | |
Discussion
HP LaserJet 4200/4300 Printer Arbitrary Firmware Upgrade Vulnerability
It is reported that HP LaserJet 4200 and 4300 printers are susceptible to an arbitrary firmware upgrade vulnerability.
This vulnerability is due to the method of upgrading the firmware on affected devices. According to HP upgrade documentation, these printers can upgrade their firmware by sending them specially formatted print jobs. This allows for firmware upgrades to be initiated by unauthenticated FTP access, copying firmware files to the printer via CIFS, or possibly other means as well.
It is unclear at this time what strength the in place measures are to ensure that firmware files contain legitimate firmware data for the printer. Simple CRC-32 checksums, or other similar means may allow attackers to create firmware files containing data sufficient to pass the printers built-in validity checks.
If an attacker can upgrade affected printers with arbitrary firmware files, they may be able to either crash affected machines, replace the firmware code with malicious executable code, or possibly render the printer useless until the firmware is repaired or replaced. Attackers would be able to perform this upgrade without authentication, via the network.
Other printers may also be affected.
It is reported that HP LaserJet 4200 and 4300 printers are susceptible to an arbitrary firmware upgrade vulnerability.
This vulnerability is due to the method of upgrading the firmware on affected devices. According to HP upgrade documentation, these printers can upgrade their firmware by sending them specially formatted print jobs. This allows for firmware upgrades to be initiated by unauthenticated FTP access, copying firmware files to the printer via CIFS, or possibly other means as well.
It is unclear at this time what strength the in place measures are to ensure that firmware files contain legitimate firmware data for the printer. Simple CRC-32 checksums, or other similar means may allow attackers to create firmware files containing data sufficient to pass the printers built-in validity checks.
If an attacker can upgrade affected printers with arbitrary firmware files, they may be able to either crash affected machines, replace the firmware code with malicious executable code, or possibly render the printer useless until the firmware is repaired or replaced. Attackers would be able to perform this upgrade without authentication, via the network.
Other printers may also be affected.
Exploit / POC
HP LaserJet 4200/4300 Printer Arbitrary Firmware Upgrade Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
HP LaserJet 4200/4300 Printer Arbitrary Firmware Upgrade Vulnerability
Solution:
HP has released advisory SSRT4840 along with a solution dealing with this issue. For more information on applying the solution please see the referenced vendor advisory. It should be noted that the advisory in question is accessible by registered members only.
Solution:
HP has released advisory SSRT4840 along with a solution dealing with this issue. For more information on applying the solution please see the referenced vendor advisory. It should be noted that the advisory in question is accessible by registered members only.
References
HP LaserJet 4200/4300 Printer Arbitrary Firmware Upgrade Vulnerability
References:
References: