Home / HP warns of LaserJet software flaw

HP warns of LaserJet software flaw

HP has warned that the software supplied with two of its LaserJet business printers could leave PCs open to attack by hackers.

HP has warned that the software supplied with two of its LaserJet business printers could leave PCs open to attack by hackers.

According to the firm’s vulnerability advisory - on the Tech Support section of its global website the problem lies in its ‘Toolbox’ software for Microsoft Windows.

The troublesome versions of this Toolbox program are those that were shipped with HP’s 2500 and 4600 colour laser machines, the first of which HP Middle East's website states is still on sale across the Middle East (both models have in fact now been discontinued).

The ‘Vulnerability Summary’ in question on HP’s website reads: “A potential security vulnerability has been identified in the HP Color LaserJet 2500 and 4600 Toolbox, which may allow an unauthorized remote attacker to read arbitrary files.” HP then goes on to thank Richard Horsman of Sec-1.com for reporting this vulnerability to security-alert@hp.com.

As a result, users of HP’s LaserJet 2500 and 4600 machines should safeguard their computers by installing the relevant Toolbox software updates, which HP has made available for download.

LaserJet 2500 owners should go to www.hp.com/go/clj2500_software, select ‘Download Drivers and Software’, then choose the 2500 from the product list and the OS version they are using, before downloading the ‘HP Color LaserJet 2500/4600 Software Update’ version 3.1. 4600 owners should visit www.hp.com/go/clj4600_software and then do the same.

HP’s Toolbox software is installed onto a user’s PC at the same time as HP’s LaserJet drivers. The application uses a web browser type of user interface through which owners can access printer status information and view troubleshooting tips.

Follow us to get the most comprehensive technology news in UAE delivered fresh from our social media accounts on Facebook, Twitter, Youtube, and listen to our Weekly Podcast. Click here to sign up for our weekly newsletter on curated technology news in the Middle East and Worldwide.

REGISTER NOW | Webinar Event | Security you can bank on – Safeguarding the Middle East’s financial sector

Presented in partnership with security and network specialist Cybereason, the second in the three part webinar series will bring together a panel of experts to discuss how banks and financial institutions are evolving their service offering while simultaneously staying one step ahead of the cyber criminals who seek to bring their operations crashing to the ground.