HP JetDirect Device SNMP Request Cleartext Admin Credential Disclosure

This script is Copyright (C) 2003-2011 Tenable Network Security, Inc.


Synopsis :

The administrative password of the remote HP JetDirect printer can be obtained
using SNMP.

Description :

It is possible to obtain the password of the remote HP JetDirect
web server by sending SNMP requests.

An attacker may use this information to gain administrative access
to the remote printer.

Solution :

Disable the SNMP service on the remote host if you do not use it,
or filter incoming UDP packets going to this port.

http://www.securityfocus.com/archive/1/313714/2003-03-01/2003-03-07/0

Risk factor :

High

Family: SNMP

Nessus Plugin ID: 11317 ()

Bugtraq ID: 5331
7001

CVE ID: CVE-2002-1048