CVE Vulnerabilities

CVE-2013-4613

Published: Jun 21, 2013 | Modified: Jun 24, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The default configuration of the administrative interface on the Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers does not require authentication, which allows remote attackers to modify the configuration by visiting the Advanced page. NOTE: the vendor has apparently responded by stating for user convenience, the default setting does not require a password. However, if a user has a particular concern about third parties accessing the users home printer, the default setting can be changed to add a password.

Affected Software

Name Vendor Start Version End Version
Mg3100_printer Canon - (including) - (including)
Mg5300_printer Canon - (including) - (including)
Mg6100_printer Canon - (including) - (including)
Mp340_printer Canon - (including) - (including)
Mp495_printer Canon - (including) - (including)
Mx870_printer Canon - (including) - (including)
Mx890_printer Canon - (including) - (including)
Mx920_printer Canon - (including) - (including)
Mx922_printer Canon - (including) - (including)

References