Vulnerability Database

393,494

Total vulnerabilities in the database

CVE-2011-4161 — hp / color_laserjet_enterprise_cp4520

Permissions, Privileges, and Access Controls

The default configuration of the HP CM8060 Color MFP with Edgeline; Color LaserJet 3xxx, 4xxx, 5550, 9500, CMxxxx, CPxxxx, and Enterprise CPxxxx; Digital Sender 9200c and 9250c; LaserJet 4xxx, 5200, 90xx, Mxxxx, and Pxxxx; and LaserJet Enterprise 500 color M551, 600, M4555 MFP, and P3015 enables the Remote Firmware Update (RFU) setting, which allows remote attackers to execute arbitrary code by using a session on TCP port 9100 to upload a crafted firmware update.

  • Published: Dec 1, 2011
  • Updated: Oct 4, 2026
  • CVE: CVE-2011-4161
  • Severity: High
  • Exploit:
  • CISA KEV:

CVSS v2:

  • Severity: High
  • Score: 10
  • AV:N/AC:L/Au:N/C:C/I:C/A:C

CWEs:

Software Affected versions
hp / color_laserjet_enterprise_cp4520 All versions
hp / laserjet_m5035 All versions
hp / laserjet_4250 All versions
hp / color_laserjet_cp3505 All versions
hp / color_laserjet_enterprise_cp4525 All versions
hp / laserjet_p3005 All versions
hp / laserjet_m9050 All versions
hp / laserjet_5200 All versions
hp / color_laserjet_4700 All versions
hp / color_laserjet_cm3530 All versions
hp / laserjet_9050 All versions
hp / laserjet_p4015 All versions
hp / color_laserjet_cp3525 All versions
hp / laserjet_p4014 All versions
hp / color_laserjet_3800 All versions
hp / color_laserjet_cp5525 All versions
hp / color_laserjet_cm6030 All versions
hp / laserjet_m9040 All versions
hp / laserjet_9040 All versions
hp / color_laserjet_4730_mfp All versions
hp / color_laserjet_5550 All versions
hp / laserjet_p4515 All versions
hp / color_laserjet_9500 All versions
hp / digital_sender_9250c All versions
hp / color_laserjet_3000 All versions
hp / digital_sender_9200c All versions
hp / color_laserjet_cm6040 All versions
hp / laserjet_m3035 All versions
hp / laserjet_enterprise_p3015 All versions
hp / laserjet_4350 All versions
hp / laserjet_4240 All versions
hp / color_laserjet_cp6015 All versions
hp / laserjet_4345_mfp All versions
hp / color_laserjet_cp4005 All versions
hp / color_laserjet_4730 = mfp
hp / color_laserjet_cm4540 = mfp
hp / color_laserjet_cm4730 = mfp
hp / laserjet_enterprise_500_color = m551
hp / laserjet_enterprise_600 = m601
hp / laserjet_enterprise_600 = m602
hp / laserjet_enterprise_600 = m603
hp / laserjet_enterprise_m4555 = mfp

Frequently Asked Questions

A security vulnerability is a weakness in software, hardware, or configuration that can be exploited to compromise confidentiality, integrity, or availability. Many vulnerabilities are tracked as CVEs (Common Vulnerabilities and Exposures), which provide a standardized identifier so teams can coordinate patching, mitigation, and risk assessment across tools and vendors.

CVSS (Common Vulnerability Scoring System) estimates technical severity, but it doesn't automatically equal business risk. Prioritize using context like internet exposure, affected asset criticality, known exploitation (proof-of-concept or in-the-wild), and whether compensating controls exist. A "Medium" CVSS on an exposed, production system can be more urgent than a "Critical" on an isolated, non-production host.

A vulnerability is the underlying weakness. An exploit is the method or code used to take advantage of it. A zero-day is a vulnerability that is unknown to the vendor or has no publicly available fix when attackers begin using it. In practice, risk increases sharply when exploitation becomes reliable or widespread.

Recurring findings usually come from incomplete Asset Discovery, inconsistent patch management, inherited images, and configuration drift. In modern environments, you also need to watch the software supply chain: dependencies, containers, build pipelines, and third-party services can reintroduce the same weakness even after you patch a single host. Unknown or unmanaged assets (often called Shadow IT) are a common reason the same issues resurface.

Use a simple, repeatable triage model: focus first on externally exposed assets, high-value systems (identity, VPN, email, production), vulnerabilities with known exploits, and issues that enable remote code execution or privilege escalation. Then enforce patch SLAs and track progress using consistent metrics so remediation is steady, not reactive.

SynScan combines attack surface monitoring and continuous security auditing to keep your inventory current, flag high-impact vulnerabilities early, and help you turn raw findings into a practical remediation plan.