// For flags

CVE-2021-20877

 

Severity Score

4.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series (MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series (LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS (LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER (2206IF, 2204N, and 2204F) sold in Europe) allows remote attackers to inject an arbitrary script via unspecified vectors.

Una vulnerabilidad de tipo cross-site scripting en las impresoras láser y multifuncionales de pequeña oficina de Canon (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, y MF229dw/MF224dw/MF222dw vendidos en Japón, la serie MF imageCLASS (MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW VP, y MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) y la serie imageCLASS LBP (LBP113W/LBP151DW/LBP162DW ) vendidas en EE.UU., e iSENSYS (LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w y MF4890dw) y imageRUNNER (2206IF, 2204N y 2204F) vendidos en Europa) permite a atacantes remotos inyectar un script arbitrario por medio de vectores no especificados

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-12-17 CVE Reserved
  • 2022-02-08 CVE Published
  • 2023-12-26 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Canon
Search vendor "Canon"
2204f
Search vendor "Canon" for product "2204f"
--
Affected
Canon
Search vendor "Canon"
2204n
Search vendor "Canon" for product "2204n"
--
Affected
Canon
Search vendor "Canon"
2206if
Search vendor "Canon" for product "2206if"
--
Affected
Canon
Search vendor "Canon"
Lbp113w
Search vendor "Canon" for product "Lbp113w"
--
Affected
Canon
Search vendor "Canon"
Lbp151dw
Search vendor "Canon" for product "Lbp151dw"
--
Affected
Canon
Search vendor "Canon"
Lbp162
Search vendor "Canon" for product "Lbp162"
--
Affected
Canon
Search vendor "Canon"
Lbp162dw
Search vendor "Canon" for product "Lbp162dw"
--
Affected
Canon
Search vendor "Canon"
Lbp162l
Search vendor "Canon" for product "Lbp162l"
--
Affected
Canon
Search vendor "Canon"
Mf113w
Search vendor "Canon" for product "Mf113w"
--
Affected
Canon
Search vendor "Canon"
Mf212w
Search vendor "Canon" for product "Mf212w"
--
Affected
Canon
Search vendor "Canon"
Mf217w
Search vendor "Canon" for product "Mf217w"
--
Affected
Canon
Search vendor "Canon"
Mf222dw
Search vendor "Canon" for product "Mf222dw"
--
Affected
Canon
Search vendor "Canon"
Mf224dw
Search vendor "Canon" for product "Mf224dw"
--
Affected
Canon
Search vendor "Canon"
Mf227dw
Search vendor "Canon" for product "Mf227dw"
--
Affected
Canon
Search vendor "Canon"
Mf229dw
Search vendor "Canon" for product "Mf229dw"
--
Affected
Canon
Search vendor "Canon"
Mf232w
Search vendor "Canon" for product "Mf232w"
--
Affected
Canon
Search vendor "Canon"
Mf237w
Search vendor "Canon" for product "Mf237w"
--
Affected
Canon
Search vendor "Canon"
Mf242dw
Search vendor "Canon" for product "Mf242dw"
--
Affected
Canon
Search vendor "Canon"
Mf244dw
Search vendor "Canon" for product "Mf244dw"
--
Affected
Canon
Search vendor "Canon"
Mf245dw
Search vendor "Canon" for product "Mf245dw"
--
Affected
Canon
Search vendor "Canon"
Mf247dw
Search vendor "Canon" for product "Mf247dw"
--
Affected
Canon
Search vendor "Canon"
Mf249dw
Search vendor "Canon" for product "Mf249dw"
--
Affected
Canon
Search vendor "Canon"
Mf262dw
Search vendor "Canon" for product "Mf262dw"
--
Affected
Canon
Search vendor "Canon"
Mf264dw
Search vendor "Canon" for product "Mf264dw"
--
Affected
Canon
Search vendor "Canon"
Mf265dw
Search vendor "Canon" for product "Mf265dw"
--
Affected
Canon
Search vendor "Canon"
Mf267dw
Search vendor "Canon" for product "Mf267dw"
--
Affected
Canon
Search vendor "Canon"
Mf269dw
Search vendor "Canon" for product "Mf269dw"
--
Affected
Canon
Search vendor "Canon"
Mf269dw Vp
Search vendor "Canon" for product "Mf269dw Vp"
--
Affected
Canon
Search vendor "Canon"
Mf4570dn
Search vendor "Canon" for product "Mf4570dn"
--
Affected
Canon
Search vendor "Canon"
Mf4570dw
Search vendor "Canon" for product "Mf4570dw"
--
Affected
Canon
Search vendor "Canon"
Mf4770n
Search vendor "Canon" for product "Mf4770n"
--
Affected
Canon
Search vendor "Canon"
Mf4780w
Search vendor "Canon" for product "Mf4780w"
--
Affected
Canon
Search vendor "Canon"
Mf4880dw
Search vendor "Canon" for product "Mf4880dw"
--
Affected
Canon
Search vendor "Canon"
Mf4890dw
Search vendor "Canon" for product "Mf4890dw"
--
Affected