PT-2018-10970 · Canon · Canon Lbp6030W

CVE-2018-12049

·

Publicado

2018-06-08

·

Atualizado

2024-08-05

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Canon LBP6030w (affected versions not specified)
Description A remote attacker can bypass the System Manager Mode on the Canon LBP6030w web interface without a PIN for "/checkLogin.cgi" via vectors involving "/portal top.html" to get full access to the device. The vendor reportedly responded that this issue occurs when a customer keeps the default settings without using the countermeasures and best practices shown in the documentation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-12049

Produtos afetados

Canon Lbp6030W