Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Advisories

December 6th, 2011, 08:02 GMT · By Eduard Kovacs

HP Publishes List of LaserJet Printers Susceptible to Malicious Firmware Update

SHARE:

Adjust text size:


HP LaserJet Enterprise 600 M601 is one of the devices on the list
Enlarge picture
After the controversial study about HP LaserJet printers that can be set on fire was released to the public, HP quickly came forward to defend its reputation. The first move they made was to publish the list of devices that could be impacted by the installation of an unauthorized printer firmware.

“A potential security vulnerability has been identified with certain HP printers and HP digital senders. The vulnerability could be exploited remotely to install unauthorized printer firmware,” reads the security bulletin issued by HP.

HP LaserJet Enterprise 500 color M551, HP LaserJet Enterprise 600 M602, HP LaserJet M3035, HP Color LaserJet CP4005, HP LaserJet P4515 and HP LaserJet Enterprise M4555 MFP are just a few of the models out of the 40 or so listed by the company.

Basically, customers who purchased HP LaserJet models that were manufactured before 2009, may be susceptible to the attack.

Meanwhile, until they come up with a more permanent solution to the issue, an advisory was published so customers can learn how to secure their devices against a potential unauthorized access.

Since the Remote Firmware Update (RFU) is enabled by default, an update can be sent remotely to port 9100 without authentication, which could allow for someone to alter the machine’s firmware. Users are advised to disable the Printer Firmware Update and consult the paper called HP Imaging and Printing Security Best Practices.

“HP is broadly distributing this Security Bulletin in order to bring to the attention of users of the affected HP products the important security information contained in this Bulletin. HP recommends that all users determine the applicability of this information to their individual situations and take appropriate action,” reads the advisory.

Individuals and companies who rely on the LaserJet printers released before 2009 are recommended to check out the complete list and, if their device is on it, they should immediately follow the measures suggested by HP.

TELL US WHAT YOU THINK:

2,806 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


HP Printers May Be Remotely Set On Fire, Researchers Say

HP: 'Thermal Breakers' Installed in Printers Prevent Fires

HP Called to Court for Not Warning Customers on the LaserJet Flaws

Symantec: Polymorphic Malware Increased in September

Office Printer Emails Hide Malware

READER COMMENTS:


Comment #1 by: kukui on 10 Dec 2011, 02:38 UTC reply to this comment

This is a fine and fast printer, but HP makes it hard to fix this problem. Also, the printer will not print a single check using Quicken....Quicken and HP cannot fix the problem.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM