CVE-2011-4161 - CVE House
Back to Database
Status published Critical CVE-2011-4161

The default configuration of the HP CM8060 Color MFP with...

Vulnerability Description

The default configuration of the HP CM8060 Color MFP with Edgeline; Color LaserJet 3xxx, 4xxx, 5550, 9500, CMxxxx, CPxxxx, and Enterprise CPxxxx; Digital Sender 9200c and 9250c; LaserJet 4xxx, 5200, 90xx, Mxxxx, and Pxxxx; and LaserJet Enterprise 500 color M551, 600, M4555 MFP, and P3015 enables the Remote Firmware Update (RFU) setting, which allows remote attackers to execute arbitrary code by using a session on TCP port 9100 to upload a crafted firmware update.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-4161

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

color laserjet 3000, color laserjet 3800, color laserjet 4700, color laserjet 4730, color laserjet 4730 mfp, color laserjet 5550, color laserjet 9500, color laserjet cm3530, color laserjet cm4540, color laserjet cm4730, color laserjet cm6030, color laserjet cm6040, color laserjet cp3505, color laserjet cp3525, color laserjet cp4005, color laserjet cp5525, color laserjet cp6015, color laserjet enterprise cp4520, color laserjet enterprise cp4525, color mfp cm8060, digital sender 9200c, digital sender 9250c, laserjet 4240, laserjet 4250, laserjet 4345 mfp, laserjet 4350, laserjet 5200, laserjet 9040, laserjet 9050, laserjet enterprise 500 color, laserjet enterprise 600, laserjet enterprise m4555, laserjet enterprise p3015, laserjet m3035, laserjet m5035, laserjet m9040, laserjet m9050, laserjet p3005, laserjet p4014, laserjet p4015, laserjet p4515
Vulnerable Versions:
mfp, m551, m601, m602, m603

Timeline

Official Publish: December 1st, 2011
Last Modified: August 7th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.