PT-2013-5097 · Canon · Canon Mx340+8
Hostess
+1
·
Publicado
2013-06-21
·
Atualizado
2013-06-24
·
CVE-2013-4615
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Canon MG3100
Canon MG5300
Canon MG6100
Canon MP495
Canon MX340
Canon MX870
Canon MX890
Canon MX920
Canon MX922
Description
The issue allows remote attackers to cause a denial of service, resulting in a device hang, by sending a crafted
LAN TXT24 parameter to the "English/pages MacUS/cgi lan.cgi" API endpoint, followed by a direct request to "English/pages MacUS/lan set content.html".Recommendations
For each of the affected Canon printer models, consider restricting access to the
cgi lan.cgi and lan set content.html endpoints to minimize the risk of exploitation.
As a temporary workaround, avoid using the LAN TXT24 parameter in the affected API endpoint until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Canon Mg3100
Canon Mg5300
Canon Mg6100
Canon Mp495
Canon Mx340
Canon Mx870
Canon Mx890
Canon Mx920
Canon Mx922