Executive brief
HP LaserJet printers equipped with JetDirect network cards may be configured without administrative passwords by default. This allows any user on the network to remotely access the printer's management interface to change its IP address, disable logging, or bypass print accounting. Such unauthorized access can lead to service disruptions, loss of administrative control, and unmonitored use of printing resources.
Technical details
HP LaserJet printers (specifically tested on 4M Plus) using JetDirect cards with TCP/IP enabled often lack a default administrative password. Attackers can connect via Telnet (port 23) to modify critical network settings like the IP address or disable system logging. Additionally, the device accepts direct PostScript data on TCP ports 9099 and 9100, allowing attackers to bypass LPD-based print accounting and access control. The vulnerability is exploitable over the network without authentication. Mitigation involves placing the printers behind a firewall or within a restricted network segment.
Affected products
- HP LaserJet 4M Plus JetDirect cards with TCP/IP enabled
- HP LaserJet 5M JetDirect cards with TCP/IP enabled
Timeline
- 1997-10-04: disclosed: Initial discovery reported on Bugtraq mailing list
- 1997-10-04: advisory: NVD published date