CVE-2021-20877 Information
Description
Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162 MF4890dw MF269dw/MF265dw/MF264dw/MF262dw MF249dw/MF245dw/MF244dw/MF242dw/MF232w and MF229dw/MF224dw/MF222dw sold in Japan imageCLASS MF Series (MF113W/MF212W/MF217W/MF227DW/MF229DW MF232W/MF244DW/MF247DW/MF249DW MF264DW/MF267DW/MF269DW/MF269DW VP and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series (LBP113W/LBP151DW/LBP162DW ) sold in the US and iSENSYS (LBP162DW LBP113W LBP151DW MF269dw MF267dw MF264dw MF113w MF249dw MF247dw MF244dw MF237w MF232w MF229dw MF217w MF212w MF4780w and MF4890dw) and imageRUNNER (2206IF 2204N and 2204F) sold in Europe) allows remote attackers to inject an arbitrary script via unspecified vectors.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Reference
https://cweb.canon.jp/e-support/info/211221xss.html https://jvn.jp/en/jp/JVN64806328/index.html https://jvn.jp/jp/JVN64806328/index.html https://www.canon-europe.com/support/product-security-latest-news/ https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/Service-Notice-Canon-Laser-Printer-and-Small-Office-Multifunctional-Printer-related-to-cross-site-scripting
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
4.8
Share on: