HP LaserJet Printers Missing Authorization (CVE-2013-4807)

high Tenable OT Security Plugin ID 505350

Synopsis

The remote OT asset is affected by a vulnerability.

Description

Unspecified vulnerability on the HP LaserJet Pro P1102w, P1606dn, M1212nf MFP, M1213nf MFP, M1214nfh MFP, M1216nfh MFP, M1217nfw MFP, M1218nfs MFP, and CP1025nw with firmware before 20130703 allows remote attackers to modify data via unknown vectors.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

http://www.nessus.org/u?465688dd

http://osvdb.org/95907

http://www.securityfocus.com/bid/61565

http://www.securitytracker.com/id/1028869

https://exchange.xforce.ibmcloud.com/vulnerabilities/86178

Plugin Details

Severity: High

ID: 505350

File Name: tenable_ot_hp_CVE-2013-4807.nasl

Version: 1.1

Type: Remote

Family: Tenable.ot

Published: 5/26/2026

Updated: 5/26/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: High

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N

CVSS Score Source: CVE-2013-4807

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Vulnerability Information

CPE: cpe:/h:hp:laserjet_pro_cp1025nw_firmware:20130703, cpe:/h:hp:laserjet_pro_m1212nf_mfp_firmware:20130703, cpe:/h:hp:laserjet_pro_m1213nf_mfp_firmware:20130703, cpe:/h:hp:laserjet_pro_m1214nfh_mfp_firmware:20130703, cpe:/h:hp:laserjet_pro_m1216nfh_multifunction_printer_firmware:20130703, cpe:/h:hp:laserjet_pro_m1217nfw_multifunction_printer_firmware:20130703, cpe:/h:hp:laserjet_pro_p1102w_firmware:20130703, cpe:/h:hp:laserjet_pro_m1218nfs_mfp_firmware:20130703, cpe:/h:hp:laserjet_pro_p1606dn_firmware:20130703

Required KB Items: Tenable.ot/HP

Patch Publication Date: 8/5/2013

Vulnerability Publication Date: 8/5/2013

Reference Information

CVE: CVE-2013-4807

CWE: 862