CVE-2012-5221 - CVE House
Back to Database
Status published Medium CVE-2012-5221

Directory traversal vulnerability in the PostScript Interpreter, as used on...

Vulnerability Description

Directory traversal vulnerability in the PostScript Interpreter, as used on the HP LaserJet 4xxx, 5200, 90xx, M30xx, M4345, M50xx, M90xx, P3005, and P4xxx; LaserJet Enterprise P3015; Color LaserJet 3xxx, 47xx, 5550, 9500, CM60xx, CP35xx, CP4005, and CP6015; Color LaserJet Enterprise CP4xxx; and 9250c Digital Sender with model-dependent firmware through 52.x allows remote attackers to read arbitrary files via unknown vectors.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-5221

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

color laserjet 3000, color laserjet 3800, color laserjet 4700, color laserjet 4730 mfp, color laserjet 5550, color laserjet 9500 mfp, color laserjet cm6030 mfp, color laserjet cm6040 mfp, color laserjet cp3505, color laserjet cp3525, color laserjet cp4005, color laserjet cp6015, color laserjet enterprise cp4025, color laserjet enterprise cp4525, digital sender 9250c, laserjet 4240, laserjet 4250, laserjet 4345 mfp, laserjet 4350, laserjet 5200l, laserjet 5200n, laserjet 9040, laserjet 9040 mfp, laserjet 9050, laserjet 9050 mfp, laserjet enterprise p3015, laserjet m3027 mfp, laserjet m3035 mfp, laserjet m4345 mfp, laserjet m5025 mfp, laserjet m5035 mfp, laserjet m9040 mpf, laserjet m9050 mpf, laserjet p3005, laserjet p4014, laserjet p4015, laserjet p4515
Vulnerable Versions:
q7534a, q5981a, q7492a, cb480a, q3714a, c8549a, ce664a, q3939a, cb442a, cc469a, cb503a, q3932a, cc490a, cc493a, cb472a, q7785a, q5400a, q3942a, q5407a, q7543a, q7697a, q3721a, ce526a, cb416a, cb414a, cc519a, cb425a, q7840a, q7829a, cc394a, cc395a, q7812a, cb507a, cb509a, cb514a

Timeline

Official Publish: April 29th, 2013
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.