PT-2013-5097 · Canon · Canon Mx340+8
Hostess
+1
·
Published
2013-06-21
·
Updated
2013-06-24
·
CVE-2013-4615
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Canon MG3100
Canon MG5300
Canon MG6100
Canon MP495
Canon MX340
Canon MX870
Canon MX890
Canon MX920
Canon MX922
Description
The issue allows remote attackers to cause a denial of service, resulting in a device hang, by sending a crafted
LAN TXT24 parameter to the "English/pages MacUS/cgi lan.cgi" API endpoint, followed by a direct request to "English/pages MacUS/lan set content.html".Recommendations
For each of the affected Canon printer models, consider restricting access to the
cgi lan.cgi and lan set content.html endpoints to minimize the risk of exploitation.
As a temporary workaround, avoid using the LAN TXT24 parameter in the affected API endpoint until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Canon Mg3100
Canon Mg5300
Canon Mg6100
Canon Mp495
Canon Mx340
Canon Mx870
Canon Mx890
Canon Mx920
Canon Mx922