PT-2013-5097 · Canon · Canon Mx340+8

Hostess

+1

·

Publicado

2013-06-21

·

Atualizado

2013-06-24

·

CVE-2013-4615

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Canon MG3100 Canon MG5300 Canon MG6100 Canon MP495 Canon MX340 Canon MX870 Canon MX890 Canon MX920 Canon MX922
Description The issue allows remote attackers to cause a denial of service, resulting in a device hang, by sending a crafted LAN TXT24 parameter to the "English/pages MacUS/cgi lan.cgi" API endpoint, followed by a direct request to "English/pages MacUS/lan set content.html".
Recommendations For each of the affected Canon printer models, consider restricting access to the cgi lan.cgi and lan set content.html endpoints to minimize the risk of exploitation. As a temporary workaround, avoid using the LAN TXT24 parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-4615

Produtos afetados

Canon Mg3100
Canon Mg5300
Canon Mg6100
Canon Mp495
Canon Mx340
Canon Mx870
Canon Mx890
Canon Mx920
Canon Mx922