Executive brief
HP LaserJet printers equipped with JetDirect network cards contain a security flaw that allows unauthorized users to bypass print filters and accounting systems. By sending print jobs directly to specific network ports, an attacker can print documents without authorization or change the printer's network configuration. This can lead to unauthorized resource usage, disclosure of sensitive printed information, or disruption of printing services.
Technical details
The vulnerability exists in the JetDirect network interface cards used in HP LaserJet printers when configured with TCP/IP. The device fails to restrict access to raw print channels on TCP ports 9099 and 9100, allowing attackers to bypass the standard Line Printer Daemon (LPD) service and any associated print filters or page accounting mechanisms. Additionally, the lack of IP-based access controls allows remote attackers to connect via Telnet (port 23) to modify device settings, such as IP addresses or logging configurations. This is a network-based attack requiring no authentication. Mitigation involves placing the affected printers behind a firewall to restrict access to authorized print servers only.
Affected products
- HP LaserJet 4M Plus JetDirect card firmware with TCP/IP enabled
- HP LaserJet 5M JetDirect card firmware with TCP/IP enabled
Timeline
- 1997-10-04: disclosed: Initial disclosure on Bugtraq mailing list
- 1997-10-04: advisory: NVD published date