9 lines
No EOL
704 B
Text
9 lines
No EOL
704 B
Text
HP JetDirect J2552A/J2552B/J2591A/J3110A/J3111A/J3113A/J3263A/300.0 X Printer SNMP JetAdmin Device Password Disclosure Vulnerability
|
|
|
|
source: https://www.securityfocus.com/bid/7001/info
|
|
|
|
A problem with JetDirect printers could make it possible for a remote user to gain administrative access to the printer.
|
|
|
|
It has been reported that HP JetDirect printers leak the web JetAdmin device password under some circumstances. By sending an SNMP GET request to a vulnerable printer, the printer will return the hex-encoded device password to the requester. This could allow a remote user to access and change configuration of the printer.
|
|
|
|
C:\>snmputil get example.printer public .1.3.6.1.4.1.11.2.3.9.1.1.13.0 |