CVE-2021-20877 Information

Description

Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162 MF4890dw MF269dw/MF265dw/MF264dw/MF262dw MF249dw/MF245dw/MF244dw/MF242dw/MF232w and MF229dw/MF224dw/MF222dw sold in Japan imageCLASS MF Series (MF113W/MF212W/MF217W/MF227DW/MF229DW MF232W/MF244DW/MF247DW/MF249DW MF264DW/MF267DW/MF269DW/MF269DW VP and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series (LBP113W/LBP151DW/LBP162DW ) sold in the US and iSENSYS (LBP162DW LBP113W LBP151DW MF269dw MF267dw MF264dw MF113w MF249dw MF247dw MF244dw MF237w MF232w MF229dw MF217w MF212w MF4780w and MF4890dw) and imageRUNNER (2206IF 2204N and 2204F) sold in Europe) allows remote attackers to inject an arbitrary script via unspecified vectors.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Reference

https://cweb.canon.jp/e-support/info/211221xss.html https://jvn.jp/en/jp/JVN64806328/index.html https://jvn.jp/jp/JVN64806328/index.html https://www.canon-europe.com/support/product-security-latest-news/ https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/Service-Notice-Canon-Laser-Printer-and-Small-Office-Multifunctional-Printer-related-to-cross-site-scripting

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction Required

HIGH

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

4.8

Share on: