PT-2018-10769 · Canon · Canon Mf220+1

Published

2018-06-04

·

Updated

2024-08-05

·

CVE-2018-11711

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Canon MF210 and MF220 versions (affected versions not specified)
Description A remote attacker can bypass the System Manager Mode on the Canon MF210 and MF220 web interface without knowing the PIN for "/login.html" via vectors involving "/portal top.html" to get full access to the device. The vendor reportedly responded that this issue occurs when a customer keeps the default settings without using the countermeasures and best practices shown in the documentation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2018-11711

Affected Products

Canon Mf210
Canon Mf220