HP says security flaw is real, but flames are unlikely

Share this article:

Hewlett-Packard has shot down claims that a vulnerability in some of its printers could be used to set the devices on fire.

Researchers at Columbia University in New York this week said they discovered a flaw in HP LaserJet printers that could allow attackers to steal sensitive documents, gain control of corporate networks, or even set the affected devices on fire.

These exploits could be accomplished because some HP LaserJet printers do not validate the origin of remote firmware updates before applying them, Salvatore Stolfo, a professor of computer science at Columbia who directed the research, told SCMagazineUS.com on Tuesday. That means anyone can reprogram the devices with malicious firmware.

In lab demonstrations, the researchers even were able to leverage the vulnerability to overheat the printer's fuser – a ink-drying component –  to cause paper to turn brown and smoke. In that demonstration, a thermal switch shut the printer down before a fire was started.

But HP dismissed the notion that the printers could ignite.

"HP LasterJet printers have a hardware element called a thermal breaker that is designed to prevent the fuser from overheating or causing a fire," according to a statement, issued late Tuesday. "It cannot be overcome by a firmware change or this proposed vulnerability."

While the company said it was not aware of any customers being affected in any way by the bug, it admitted the possibility of successful exploit exists.

"The specific vulnerability exists for some HP LaserJet devices if placed on a public internet without a firewall," the statement said. "In a private network, some printers may be vulnerable if a malicious effort is made to modify the firmware of the device by a trusted party on the network. In some Linux or Mac environments, it may be possible for a specially formatted corrupt print job to trigger a firmware upgrade."

The company is working on a firmware fix.

Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

TOP COMMENTS

More in News

Adobe exploit used to spread Dyre credential stealer

Adobe exploit used to spread Dyre credential stealer

Users running vulnerable Adobe software could be in danger of having credentials for Bitcoin websites stolen.

Staples is investigating a potential issue involving credit card data

Staples is investigating a potential issue involving credit ...

The company said it is investigating a potential issue involving credit card data and that customers are not responsible for fraudulent activity on cards if an issue is discovered.

Skills set a priority over legacy prejudices, experts say

Skills set a priority over legacy prejudices, experts ...

Cybersecurity expert Winn Schwartau and Robert Clark, a cyber law attorney at the Army Cyber Institute, discussed issues around hiring in the information security industry.