3 results (0.003 seconds)

CVSS: 4.6EPSS: 8%CPEs: 9EXPL: 2

18 Jun 2013 — English/pages_MacUS/wls_set_content.html on the Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers shows the Wi-Fi PSK passphrase in cleartext, which allows physically proximate attackers to obtain sensitive information by reading the screen of an unattended workstation. English/pages_MacUS/wls_set_content.html en impresoras Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, y MX922 muestra la contraseña de paso (passphrase) en texto plano, lo que permite a ata... • https://packetstorm.news/files/id/181201 • CWE-255: Credentials Management Errors •

CVSS: 7.5EPSS: 66%CPEs: 9EXPL: 2

18 Jun 2013 — The Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers allow remote attackers to cause a denial of service (device hang) via a crafted LAN_TXT24 parameter to English/pages_MacUS/cgi_lan.cgi followed by a direct request to English/pages_MacUS/lan_set_content.html. NOTE: the vendor has apparently responded by stating "Canon believes that its printers will not have to deal with unauthorized access to the network from an external location as long as the printers are used in a se... • https://packetstorm.news/files/id/180511 • CWE-20: Improper Input Validation •

CVSS: 9.1EPSS: 0%CPEs: 9EXPL: 1

18 Jun 2013 — The default configuration of the administrative interface on the Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers does not require authentication, which allows remote attackers to modify the configuration by visiting the Advanced page. NOTE: the vendor has apparently responded by stating "for user convenience, the default setting does not require a password. However, if a user has a particular concern about third parties accessing the user's home printer, the default setti... • https://packetstorm.news/files/id/122073 • CWE-264: Permissions, Privileges, and Access Controls •