[] NeoSense

HP JetDirect J3111A - Invalid FTP Command Denial of Service

Author: Peter Grundl
type: dos
platform: hardware
port: 
date_added: 2000-07-19 
date_updated: 2012-07-25 
verified: 1 
codes: CVE-2000-0636;OSVDB-1471 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/1491/info

HP JetDirect firmware is vulnerable to a Denial of Service attack. JetDirect devices have an FTP service which fails to properly handle bad FTP commands sent with the ftp "quote" command. This causes the device to stop responding and possibly display an error message. Powering the device off and on is required to regain normal functionality.

ftp <printer address>
quote AAAAAAAAAAA