SECURITY ALERT: Certain HP LaserJet Printers, HP Color LaserJet Printers, and HP Digital Senders, Remote Unauthorized Access to Files - Bits and Dots -
SECURITY ALERT: Certain HP LaserJet Printers, HP Color LaserJet Printers, and HP Digital Senders, Remote Unauthorized Access to Files

HP recently identified and fixed a significant security vulnerability that can allow unauthorized access to files from remote.  This can apply to certain HP LaserJet, Color LaserJet, and Digital Senders.  According to published documentation, the following products and firmware revisions are affected:

HP LaserJet 2410 with firmware prior to 20080819 SPCL112A
HP LaserJet 2420 with firmware prior to 20080819 SPCL112A
HP LaserJet 2430 with firmware prior to 20080819 SPCL112A
HP LaserJet 4250 with firmware prior to 20080819 SPCL015A
HP LaserJet 4350 with firmware prior to 20080819 SPCL015A
HP LaserJet 9040 with firmware prior to 20080819 SPCL110A
HP LaserJet 9050 with firmware prior to 20080819 SPCL110A
HP LaserJet 4345mfp with firmware prior to 09.120.9
HP Color LaserJet 4730mfp with firmware prior to 46.200.9
HP LaserJet 9040mfp with firmware prior to 08.110.9
HP LaserJet 9050mfp with firmware prior to 08.110.9
HP 9200C Digital Sender with firmware prior to 09.120.9
HP Color LaserJet 9500mfp with firmware prior to 08.110.9

You can get more detail from the following URL.  HP recommends patching your devices at the earliest reasonable opportunity. 

http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01623905


Posted 02-09-2009 8:39 PM by Brent Follett
Filed under: , ,

Comments

Darrel wrote re: SECURITY ALERT: Certain HP LaserJet Printers, HP Color LaserJet Printers, and HP Digital Senders, Remote Unauthorized Access to Files
on 02-11-2009 2:42 PM

I have been able to update our 4250/4350 printers to the SPCL015A firmware, but I am having difficulty pushing the SPCL110A firmware to our 9050's.  I have tried through Web JetAdmin (10.1.55407), and I have copied the RFU to the ftp site of the printer.  The printer shows Receiving Update for a bit, but then goes to ready with no restart or update to the firmware.  The only clue I get is a 99.00.01 in the event log, which doesn't seem to have any information on the web.

And yes, these are 9050's and not 9050 mfp's (which we also have).

Any thoughts?

Brent Follett wrote re: SECURITY ALERT: Certain HP LaserJet Printers, HP Color LaserJet Printers, and HP Digital Senders, Remote Unauthorized Access to Files
on 02-11-2009 11:41 PM

Hello Darrel,

The only thing I can suggest is that you might want to try restarting the device after it goes back to "Ready", and see if the firmware did in fact get updated.

If the firmware didn't update for some reason, you may want to contact 1-800-HPINVENT and report an issue with the firmware.  They could investigate and take ownership of any issues as necessary.

I hope that helps.

Regards,

Brent.

T S Person wrote re: SECURITY ALERT: Certain HP LaserJet Printers, HP Color LaserJet Printers, and HP Digital Senders, Remote Unauthorized Access to Files
on 02-19-2009 9:52 PM

I have applied the firmware referenced from the rev.2  Security Bulletin for the 2430 model and instead of the printer re-initializing I get an error message "49.4C18 Service Error". I power cycle the printer and it then re-initializes fine and the firmware "appears" to have update. But I am concerned about this error and do not wish to brick a printer. Is this normal and I can proceed with out issue? I apply the firmware using the Embedded Web Server.

Brian R. Kneebone wrote re: SECURITY ALERT: Certain HP LaserJet Printers, HP Color LaserJet Printers, and HP Digital Senders, Remote Unauthorized Access to Files
on 02-22-2009 10:44 PM

Hi TS, I generally don't recommend using the "Print Now" feature in the EWS to update firmware.  Maybe it's fine, but I prefer to use the lower-level functions like FTP or spooling like a print job.  If you're getting an error once the firmware has updated, you can re-push it "just in case".  If this error is pretty consistent, I'd suggest you call it into your support desk so that it can be qualified further.  Generally speaking if the installed personalities and options reflect the read-me (e.g. DC Controller, Formatter, etc. version match on the coniguration page with what's in the readme), then you're usually fine.  When in doubt, push again though.  Regards, B.

Jean wrote re: SECURITY ALERT: Certain HP LaserJet Printers, HP Color LaserJet Printers, and HP Digital Senders, Remote Unauthorized Access to Files
on 03-03-2009 8:12 PM

I have a 4550 Color Laser Jet Printer that has an error code of 57.3 on it.  I need to know what this code is and what it will cost to repair the problem (parts).  My model is C7085A and my Serial Number is <BRK: removed for privacy reasons>.  I called your company and the lady I spoke with said to send you an email and you could answer what the 57.3 code is and help  me.

Thank you,

Jean Stavenger

<BRK: Customer information removed for privacy reasons>

Brian R. Kneebone wrote re: SECURITY ALERT: Certain HP LaserJet Printers, HP Color LaserJet Printers, and HP Digital Senders, Remote Unauthorized Access to Files
on 03-06-2009 2:04 AM

Hi Jean,

I'm not sure who recommended you ask this blog to quote out the service, but this isn't what we do here.  That said, I like to be helpful where possible, so I did a quick search on the support portal (www.hp.com/go/support) for your product, and found this article under the section labelled "Troubleshoot a problem" -> "Error messages displayed on control panel" -> "HP Color LaserJet 4500 and 4550 Series Printers - Resolving Numbered Error Messages on the Control Panel "

h20000.www2.hp.com/.../Document.jsp

If the drawer is properly closing there could just be a connector loose or something off about the fan.  If you require a service call on your printer, you have a couple of options:

Option 1: Contact an HP Authorised Service Provider.  From your address information (which I've kept private) I can tell you're in the US.  Here's the URL to locate a service provider in your area who can perform the work on behalf of HP and quote you accordingly.

h20465.www2.hp.com/.../search.aspx

Option 2: If you know exactly what the part is and just want to order it from HP doing the work yourself, you can look up parts and buy accordingly from the "Part Surfer" website:

http://partsurfer.hp.com

Option 3: If you'd like, you can ask the people at 1-800-HP-INVENT for a support call on your product.  There will be a charge on a credit card required to troubleshoot if out of warranty over the phone.  For actual service, of course that may only be available to quote by dispatching a technician depending on the results of your call which may incur other costs.

Option 4: If you're working with Hewlett-Packard under a service agreement, of course, I'd recommend you approach your service delivery or account delivery manager.  If not and you'd like to, contact an HP sales representative where custom services can be quoted for your needs.

I hope this helps.  Good luck with troubleshooting.  Take care, B.

Mujtaba Rizvi wrote re: SECURITY ALERT: Certain HP LaserJet Printers, HP Color LaserJet Printers, and HP Digital Senders, Remote Unauthorized Access to Files
on 08-19-2009 5:42 AM

I want Hp 4350 Usage page reading back Codes plz

Brian R. Kneebone wrote re: SECURITY ALERT: Certain HP LaserJet Printers, HP Color LaserJet Printers, and HP Digital Senders, Remote Unauthorized Access to Files
on 09-04-2009 4:57 AM

Hi Mujtaba, the usage page can be printed at the front panel under the "information" menu.  If you're referring to the need to update incorrect page counters and wishing to use the service pin, this is a privaledged login for service technicians authorized by HP.  Place a service call with your service partner of choice (or by calling into HP).  Fees will likely apply if out of warranty.  Regards, B.

Powered by Community Server (Non-Commercial Edition), by Telligent Systems