Search
Find a vulnerability
Search criteria
68 vulnerabilities by canon
CVE-2026-9262 (GCVE-0-2026-9262)
Vulnerability from nvd – Published: 2026-06-15 23:40 – Updated: 2026-06-16 15:01
VLAI
EPSS
VEX
Summary
Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-06-16 15:01 UTC
CWE
- CWE-1188 - Initialization of a resource with an insecure default
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://psirt.canon/advisory-information/cp2026-005/ | vendor-advisory |
| https://canon.jp/support/support-info/260615vulne… | vendor-advisory |
| https://www.usa.canon.com/about-us/to-our-custome… | vendor-advisory |
| https://www.canon-europe.com/support/product-security/ | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Canon Inc. | EOS Network Setting Tool for Windows |
Affected:
1.5.0 or earlier
|
|
| Canon Inc. | EOS Network Setting Tool for macOS |
Affected:
1.5.0 or earlier
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-9262",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-16T15:01:20.368197Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-16T15:01:31.260Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "EOS Network Setting Tool for Windows",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "1.5.0 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "EOS Network Setting Tool for macOS",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "1.5.0 or earlier"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "This issue was discovered by Ryan Hausknecht (@haus3c)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
}
],
"value": "Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1188",
"description": "CWE-1188 Initialization of a resource with an insecure default",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-06-15T23:40:15.216Z",
"orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"shortName": "Canon"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://psirt.canon/advisory-information/cp2026-005/"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://canon.jp/support/support-info/260615vulnerability-response"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.usa.canon.com/about-us/to-our-customers/cpa2026-005-vulnerability-remediation-for-eos-network-setting-tool"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.canon-europe.com/support/product-security/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"x_generator": {
"engine": "Vulnogram 1.0.2"
}
}
},
"cveMetadata": {
"assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"assignerShortName": "Canon",
"cveId": "CVE-2026-9262",
"datePublished": "2026-06-15T23:40:15.216Z",
"dateReserved": "2026-05-21T23:14:55.152Z",
"dateUpdated": "2026-06-16T15:01:31.260Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-9261 (GCVE-0-2026-9261)
Vulnerability from nvd – Published: 2026-06-15 23:39 – Updated: 2026-06-18 03:55
VLAI
EPSS
VEX
Summary
Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-06-17 00:00 UTC
CWE
- CWE-327 - Use of a Broken or Risky Cryptographic Algorithm
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://psirt.canon/advisory-information/cp2026-005/ | vendor-advisory |
| https://canon.jp/support/support-info/260615vulne… | vendor-advisory |
| https://www.usa.canon.com/about-us/to-our-custome… | vendor-advisory |
| https://www.canon-europe.com/support/product-security/ | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Canon Inc. | EOS Network Setting Tool for Windows |
Affected:
1.5.0 or earlier
|
|
| Canon Inc. | EOS Network Setting Tool for macOS |
Affected:
1.5.0 or earlier
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-9261",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-17T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-18T03:55:38.801Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "EOS Network Setting Tool for Windows",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "1.5.0 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "EOS Network Setting Tool for macOS",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "1.5.0 or earlier"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "This issue was discovered by Ryan Hausknecht (@haus3c)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
}
],
"value": "Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "HIGH",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.6,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-327",
"description": "CWE-327: Use of a Broken or Risky Cryptographic Algorithm",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-06-15T23:39:23.700Z",
"orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"shortName": "Canon"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://psirt.canon/advisory-information/cp2026-005/"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://canon.jp/support/support-info/260615vulnerability-response"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.usa.canon.com/about-us/to-our-customers/cpa2026-005-vulnerability-remediation-for-eos-network-setting-tool"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.canon-europe.com/support/product-security/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"x_generator": {
"engine": "Vulnogram 1.0.2"
}
}
},
"cveMetadata": {
"assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"assignerShortName": "Canon",
"cveId": "CVE-2026-9261",
"datePublished": "2026-06-15T23:39:23.700Z",
"dateReserved": "2026-05-21T23:14:53.345Z",
"dateUpdated": "2026-06-18T03:55:38.801Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-9260 (GCVE-0-2026-9260)
Vulnerability from nvd – Published: 2026-06-15 23:38 – Updated: 2026-06-16 12:41
VLAI
EPSS
VEX
Summary
Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Severity
6.2 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-06-16 12:41 UTC
CWE
- CWE-321 - Use of hard-coded cryptographic key
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://psirt.canon/advisory-information/cp2026-005/ | vendor-advisory |
| https://canon.jp/support/support-info/260615vulne… | vendor-advisory |
| https://www.usa.canon.com/about-us/to-our-custome… | vendor-advisory |
| https://www.canon-europe.com/support/product-security/ | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Canon Inc. | EOS Network Setting Tool for Windows |
Affected:
1.5.0 or earlier
|
|
| Canon Inc. | EOS Network Setting Tool for macOS |
Affected:
1.5.0 or earlier
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-9260",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-16T12:41:33.426171Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-16T12:41:43.181Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "EOS Network Setting Tool for Windows",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "1.5.0 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "EOS Network Setting Tool for macOS",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "1.5.0 or earlier"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "This issue was discovered by Ryan Hausknecht (@haus3c)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
}
],
"value": "Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "LOCAL",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "NONE",
"baseScore": 6.2,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-321",
"description": "CWE-321 Use of hard-coded cryptographic key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-06-15T23:38:29.951Z",
"orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"shortName": "Canon"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://psirt.canon/advisory-information/cp2026-005/"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://canon.jp/support/support-info/260615vulnerability-response"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.usa.canon.com/about-us/to-our-customers/cpa2026-005-vulnerability-remediation-for-eos-network-setting-tool"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.canon-europe.com/support/product-security/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"x_generator": {
"engine": "Vulnogram 1.0.2"
}
}
},
"cveMetadata": {
"assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"assignerShortName": "Canon",
"cveId": "CVE-2026-9260",
"datePublished": "2026-06-15T23:38:29.951Z",
"dateReserved": "2026-05-21T23:14:51.893Z",
"dateUpdated": "2026-06-16T12:41:43.181Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-9259 (GCVE-0-2026-9259)
Vulnerability from nvd – Published: 2026-06-15 23:36 – Updated: 2026-06-16 12:43
VLAI
EPSS
VEX
Summary
Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-06-16 12:43 UTC
CWE
- CWE-295 - Improper certificate validation
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://psirt.canon/advisory-information/cp2026-005/ | vendor-advisory |
| https://canon.jp/support/support-info/260615vulne… | vendor-advisory |
| https://www.usa.canon.com/about-us/to-our-custome… | vendor-advisory |
| https://www.canon-europe.com/support/product-security/ | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Canon Inc. | EOS Network Setting Tool for Windows |
Affected:
1.5.0 or earlier
|
|
| Canon Inc. | EOS Network Setting Tool for macOS |
Affected:
1.5.0 or earlier
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-9259",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-16T12:43:13.289990Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-16T12:43:21.760Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "EOS Network Setting Tool for Windows",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "1.5.0 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "EOS Network Setting Tool for macOS",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "1.5.0 or earlier"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "This issue was discovered by Ryan Hausknecht (@haus3c)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
}
],
"value": "Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-295",
"description": "CWE-295 Improper certificate validation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-06-15T23:36:28.761Z",
"orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"shortName": "Canon"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://psirt.canon/advisory-information/cp2026-005/"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://canon.jp/support/support-info/260615vulnerability-response"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.usa.canon.com/about-us/to-our-customers/cpa2026-005-vulnerability-remediation-for-eos-network-setting-tool"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.canon-europe.com/support/product-security/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"x_generator": {
"engine": "Vulnogram 1.0.2"
}
}
},
"cveMetadata": {
"assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"assignerShortName": "Canon",
"cveId": "CVE-2026-9259",
"datePublished": "2026-06-15T23:36:28.761Z",
"dateReserved": "2026-05-21T23:14:50.204Z",
"dateUpdated": "2026-06-16T12:43:21.760Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-9258 (GCVE-0-2026-9258)
Vulnerability from nvd – Published: 2026-06-15 23:35 – Updated: 2026-06-16 12:47
VLAI
EPSS
VEX
Summary
Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-06-16 12:47 UTC
CWE
- CWE-295 - Improper certificate validation
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://psirt.canon/advisory-information/cp2026-005/ | vendor-advisory |
| https://canon.jp/support/support-info/260615vulne… | vendor-advisory |
| https://www.usa.canon.com/about-us/to-our-custome… | vendor-advisory |
| https://www.canon-europe.com/support/product-security/ | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Canon Inc. | EOS Network Setting Tool for Windows |
Affected:
1.5.0 or earlier
|
|
| Canon Inc. | EOS Network Setting Tool for macOS |
Affected:
1.5.0 or earlier
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-9258",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-16T12:47:09.464807Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-16T12:47:23.858Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "EOS Network Setting Tool for Windows",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "1.5.0 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "EOS Network Setting Tool for macOS",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "1.5.0 or earlier"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "This issue was discovered by Ryan Hausknecht (@haus3c)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
}
],
"value": "Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-295",
"description": "CWE-295 Improper certificate validation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-06-15T23:35:41.442Z",
"orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"shortName": "Canon"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://psirt.canon/advisory-information/cp2026-005/"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://canon.jp/support/support-info/260615vulnerability-response"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.usa.canon.com/about-us/to-our-customers/cpa2026-005-vulnerability-remediation-for-eos-network-setting-tool"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.canon-europe.com/support/product-security/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"x_generator": {
"engine": "Vulnogram 1.0.2"
}
}
},
"cveMetadata": {
"assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"assignerShortName": "Canon",
"cveId": "CVE-2026-9258",
"datePublished": "2026-06-15T23:35:41.442Z",
"dateReserved": "2026-05-21T23:14:48.638Z",
"dateUpdated": "2026-06-16T12:47:23.858Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2024-2184 (GCVE-0-2024-2184)
Vulnerability from nvd – Published: 2024-03-11 00:26 – Updated: 2024-08-28 20:24
VLAI
EPSS
VEX
Summary
Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF740C Series/Satera MF640C Series/Satera LBP660C Series/Satera LBP620C Series firmware v12.07 and earlier, and Satera MF750C Series/Satera LBP670C Series firmware v03.09 and earlier sold in Japan.Color imageCLASS MF740C Series/Color imageCLASS MF640C Series/Color imageCLASS X MF1127C/Color imageCLASS LBP664Cdw/Color imageCLASS LBP622Cdw/Color imageCLASS X LBP1127C firmware v12.07 and earlier, and Color imageCLASS MF750C Series/Color imageCLASS X MF1333C/Color imageCLASS LBP674Cdw/Color imageCLASS X LBP1333C firmware v03.09 and earlier sold in US.i-SENSYS MF740C Series/i-SENSYS MF640C Series/C1127i Series/i-SENSYS LBP660C Series/i-SENSYS LBP620C Series/C1127P firmware v12.07 and earlier, and i-SENSYS MF750C Series/C1333i Series/i-SENSYS LBP673Cdw/C1333P firmware v03.09 and earlier sold in Europe.
Severity
9.8 (Critical)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-03-11 15:11 UTC
CWE
- CWE-787 - Out-of-bounds Write
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://psirt.canon/advisory-information/cp2024-002/ | vendor-advisory |
Impacted products
52 products
| Vendor | Product | Version | |
|---|---|---|---|
| Canon Inc. | Color imageCLASS MF740C Series |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | Color imageCLASS MF640C Series |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | i-SENSYS MF740C Series |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | i-SENSYS MF640C Series |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | Satera MF740C Series |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | Satera MF640C Series |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | Color imageCLASS X MF1127C |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | C1127i Series |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | Color imageCLASS LBP664Cdw |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | Color imageCLASS LBP622Cdw |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | i-SENSYS LBP660C Series |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | i-SENSYS LBP620C Series |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | Satera LBP660C Series |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | Satera LBP620C Series |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | Color imageCLASS X LBP1127C |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | C1127P |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | Color imageCLASS MF750C Series |
Affected:
v03.09 and earlier
|
|
| Canon Inc. | i-SENSYS MF750C Series |
Affected:
v03.09 and earlier
|
|
| Canon Inc. | Satera MF750C Series |
Affected:
v03.09 and earlier
|
|
| Canon Inc. | Color imageCLASS X MF1333C |
Affected:
v03.09 and earlier
|
|
| Canon Inc. | C1333i Series |
Affected:
v03.09 and earlier
|
|
| Canon Inc. | Color imageCLASS LBP674Cdw |
Affected:
v03.09 and earlier
|
|
| Canon Inc. | i-SENSYS LBP673Cdw |
Affected:
v03.09 and earlier
|
|
| Canon Inc. | Satera LBP670C Series |
Affected:
v03.09 and earlier
|
|
| Canon Inc. | Color imageCLASS X LBP1333C |
Affected:
v03.09 and earlier
|
|
| Canon Inc. | C1333P |
Affected:
v03.09 and earlier
|
|
| canon | color_imageclass_mf740c_series |
Affected:
0 , ≤ 12..07
(custom)
cpe:2.3:h:canon:color_imageclass_mf740c_series:*:*:*:*:*:*:*:* |
|
| canon | color_imageclass_mf640c_series |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:color_imageclass_mf640c_series:*:*:*:*:*:*:*:* |
|
| canon | i-sensys_mf740c_series |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:i-sensys_mf740c_series:*:*:*:*:*:*:*:* |
|
| canon | i-sensys_mf640c_series |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:i-sensys_mf640c_series:*:*:*:*:*:*:*:* |
|
| canon | satera_mf740c_series |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:satera_mf740c_series:*:*:*:*:*:*:*:* |
|
| canon | color_imageclass_x_mf1127c |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:color_imageclass_x_mf1127c:*:*:*:*:*:*:*:* |
|
| canon | color_imageclass_lbp664cdw |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:color_imageclass_lbp664cdw:*:*:*:*:*:*:*:* |
|
| canon | c1127i_series |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:c1127i_series:*:*:*:*:*:*:*:* |
|
| canon | color_imageclass_lbp622cdw |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:color_imageclass_lbp622cdw:*:*:*:*:*:*:*:* |
|
| canon | i-sensys_lbp660c_series |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:i-sensys_lbp660c_series:*:*:*:*:*:*:*:* |
|
| canon | i-sensys_lbp620c_series |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:i-sensys_lbp620c_series:*:*:*:*:*:*:*:* |
|
| canon | i-sensys_mf750c_series |
Affected:
0 , ≤ 03.09
(custom)
cpe:2.3:h:canon:i-sensys_mf750c_series:*:*:*:*:*:*:*:* |
|
| canon | color_imageclass_x_lbp1333c |
Affected:
0 , ≤ 03.09
(custom)
cpe:2.3:h:canon:color_imageclass_x_lbp1333c:*:*:*:*:*:*:*:* |
|
| canon | i-sensys_lbp673cdw |
Affected:
0 , ≤ 03.09
(custom)
cpe:2.3:h:canon:i-sensys_lbp673cdw:*:*:*:*:*:*:*:* |
|
| canon | satera_lbp670c_series |
Affected:
0 , ≤ 03.09
(custom)
cpe:2.3:h:canon:satera_lbp670c_series:*:*:*:*:*:*:*:* |
|
| canon | c1333p |
Affected:
0 , ≤ 03.09
(custom)
cpe:2.3:h:canon:c1333p:*:*:*:*:*:*:*:* |
|
| canon | satera_mf640c_series |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:satera_mf640c_series:*:*:*:*:*:*:*:* |
|
| canon | satera_lbp620c_series |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:satera_lbp620c_series:*:*:*:*:*:*:*:* |
|
| canon | satera_lbp660c_series |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:satera_lbp660c_series:*:*:*:*:*:*:*:* |
|
| canon | color_imageclass_x_lbp1127c |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:color_imageclass_x_lbp1127c:*:*:*:*:*:*:*:* |
|
| canon | color_imageclass_mf750c_series |
Affected:
0 , ≤ 03.09
(custom)
cpe:2.3:h:canon:color_imageclass_mf750c_series:*:*:*:*:*:*:*:* |
|
| canon | c1127p |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:c1127p:*:*:*:*:*:*:*:* |
|
| canon | satera_mf750c_series |
Affected:
0 , ≤ 03.09
(custom)
cpe:2.3:h:canon:satera_mf750c_series:*:*:*:*:*:*:*:* |
|
| canon | color_imageclass_x_mf1333c |
Affected:
0 , ≤ 03.09
(custom)
cpe:2.3:h:canon:color_imageclass_x_mf1333c:*:*:*:*:*:*:*:* |
|
| canon | c1333i_series |
Affected:
0 , ≤ 03.09
(custom)
cpe:2.3:h:canon:c1333i_series:*:*:*:*:*:*:*:* |
|
| canon | color_imageclass_lbp674cdw |
Affected:
0 , ≤ 03.09
(custom)
cpe:2.3:h:canon:color_imageclass_lbp674cdw:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-01T19:03:39.266Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://psirt.canon/advisory-information/cp2024-002/"
}
],
"title": "CVE Program Container"
},
{
"affected": [
{
"cpes": [
"cpe:2.3:h:canon:color_imageclass_mf740c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "color_imageclass_mf740c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12..07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:color_imageclass_mf640c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "color_imageclass_mf640c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:i-sensys_mf740c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "i-sensys_mf740c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:i-sensys_mf640c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "i-sensys_mf640c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:satera_mf740c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "satera_mf740c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:color_imageclass_x_mf1127c:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "color_imageclass_x_mf1127c",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:color_imageclass_lbp664cdw:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "color_imageclass_lbp664cdw",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:c1127i_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "c1127i_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:color_imageclass_lbp622cdw:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "color_imageclass_lbp622cdw",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:i-sensys_lbp660c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "i-sensys_lbp660c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:i-sensys_lbp620c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "i-sensys_lbp620c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:i-sensys_mf750c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "i-sensys_mf750c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "03.09",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:color_imageclass_x_lbp1333c:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "color_imageclass_x_lbp1333c",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "03.09",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:i-sensys_lbp673cdw:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "i-sensys_lbp673cdw",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "03.09",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:satera_lbp670c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "satera_lbp670c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "03.09",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:c1333p:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "c1333p",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "03.09",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:satera_mf640c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "satera_mf640c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:satera_lbp620c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "satera_lbp620c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:satera_lbp660c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "satera_lbp660c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:color_imageclass_x_lbp1127c:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "color_imageclass_x_lbp1127c",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:color_imageclass_mf750c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "color_imageclass_mf750c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "03.09",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:c1127p:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "c1127p",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:satera_mf750c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "satera_mf750c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "03.09",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:color_imageclass_x_mf1333c:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "color_imageclass_x_mf1333c",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "03.09",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:c1333i_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "c1333i_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "03.09",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:color_imageclass_lbp674cdw:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "color_imageclass_lbp674cdw",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "03.09",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-2184",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-03-11T15:11:33.695685Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-08-28T20:24:54.597Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "Color imageCLASS MF740C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "Color imageCLASS MF640C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "i-SENSYS MF740C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "i-SENSYS MF640C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "Satera MF740C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "Satera MF640C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "Color imageCLASS X MF1127C",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "C1127i Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "Color imageCLASS LBP664Cdw",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "Color imageCLASS LBP622Cdw",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "i-SENSYS LBP660C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "i-SENSYS LBP620C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "Satera LBP660C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "Satera LBP620C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "Color imageCLASS X LBP1127C",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "C1127P",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "Color imageCLASS MF750C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v03.09 and earlier"
}
]
},
{
"product": "i-SENSYS MF750C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v03.09 and earlier"
}
]
},
{
"product": "Satera MF750C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v03.09 and earlier"
}
]
},
{
"product": "Color imageCLASS X MF1333C",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v03.09 and earlier"
}
]
},
{
"product": "C1333i Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v03.09 and earlier"
}
]
},
{
"product": "Color imageCLASS LBP674Cdw",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v03.09 and earlier"
}
]
},
{
"product": "i-SENSYS LBP673Cdw",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v03.09 and earlier"
}
]
},
{
"product": "Satera LBP670C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v03.09 and earlier"
}
]
},
{
"product": "Color imageCLASS X LBP1333C",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v03.09 and earlier"
}
]
},
{
"product": "C1333P",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v03.09 and earlier"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eBuffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF740C Series/Satera MF640C Series/Satera LBP660C Series/Satera LBP620C Series firmware v12.07 and earlier, and Satera MF750C Series/Satera LBP670C Series firmware v03.09 and earlier sold in Japan.Color imageCLASS MF740C Series/Color imageCLASS MF640C Series/Color imageCLASS X MF1127C/Color imageCLASS LBP664Cdw/Color imageCLASS LBP622Cdw/Color imageCLASS X LBP1127C firmware v12.07 and earlier, and Color imageCLASS MF750C Series/Color imageCLASS X MF1333C/Color imageCLASS LBP674Cdw/Color imageCLASS X LBP1333C firmware v03.09 and earlier sold in US.i-SENSYS MF740C Series/i-SENSYS MF640C Series/C1127i Series/i-SENSYS LBP660C Series/i-SENSYS LBP620C Series/C1127P firmware v12.07 and earlier, and i-SENSYS MF750C Series/C1333i Series/i-SENSYS LBP673Cdw/C1333P firmware v03.09 and earlier sold in Europe.\u003c/p\u003e"
}
],
"value": "Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF740C Series/Satera MF640C Series/Satera LBP660C Series/Satera LBP620C Series firmware v12.07 and earlier, and Satera MF750C Series/Satera LBP670C Series firmware v03.09 and earlier sold in Japan.Color imageCLASS MF740C Series/Color imageCLASS MF640C Series/Color imageCLASS X MF1127C/Color imageCLASS LBP664Cdw/Color imageCLASS LBP622Cdw/Color imageCLASS X LBP1127C firmware v12.07 and earlier, and Color imageCLASS MF750C Series/Color imageCLASS X MF1333C/Color imageCLASS LBP674Cdw/Color imageCLASS X LBP1333C firmware v03.09 and earlier sold in US.i-SENSYS MF740C Series/i-SENSYS MF640C Series/C1127i Series/i-SENSYS LBP660C Series/i-SENSYS LBP620C Series/C1127P firmware v12.07 and earlier, and i-SENSYS MF750C Series/C1333i Series/i-SENSYS LBP673Cdw/C1333P firmware v03.09 and earlier sold in Europe.\n\n"
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-787",
"description": "CWE-787: Out-of-bounds Write",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-03-11T00:26:02.346Z",
"orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"shortName": "Canon"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://psirt.canon/advisory-information/cp2024-002/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"assignerShortName": "Canon",
"cveId": "CVE-2024-2184",
"datePublished": "2024-03-11T00:26:02.346Z",
"dateReserved": "2024-03-05T00:44:00.599Z",
"dateUpdated": "2024-08-28T20:24:54.597Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2023-1764 (GCVE-0-2023-1764)
Vulnerability from nvd – Published: 2023-05-17 00:00 – Updated: 2025-01-22 19:47
VLAI
EPSS
VEX
Summary
Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the communication of the software.
Severity
6.5 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-01-22 19:47 UTC
CWE
- CWE-326 - Inadequate Encryption Strength
Assigner
References
2 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Canon Inc. | Canon IJ NW Tool |
Affected:
Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8)
|
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T05:57:24.994Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://psirt.canon/advisory-information/cp2023-002/"
},
{
"tags": [
"x_transferred"
],
"url": "https://psirt.canon/hardening/"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-1764",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-01-22T19:47:15.479601Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-01-22T19:47:20.955Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "Canon IJ NW Tool",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8)"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the communication of the software."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-326",
"description": "CWE-326: Inadequate Encryption Strength",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-05-17T00:00:00.000Z",
"orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"shortName": "Canon"
},
"references": [
{
"url": "https://psirt.canon/advisory-information/cp2023-002/"
},
{
"url": "https://psirt.canon/hardening/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"assignerShortName": "Canon",
"cveId": "CVE-2023-1764",
"datePublished": "2023-05-17T00:00:00.000Z",
"dateReserved": "2023-03-31T00:00:00.000Z",
"dateUpdated": "2025-01-22T19:47:20.955Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2023-1763 (GCVE-0-2023-1763)
Vulnerability from nvd – Published: 2023-05-17 00:00 – Updated: 2025-01-22 19:47
VLAI
EPSS
VEX
Summary
Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the software.
Severity
6.5 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-01-22 19:47 UTC
CWE
- CWE-549 - Missing Password Field Masking
Assigner
References
2 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Canon Inc. | Canon IJ NW Tool |
Affected:
Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8)
|
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T05:57:25.055Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://psirt.canon/advisory-information/cp2023-002/"
},
{
"tags": [
"x_transferred"
],
"url": "https://psirt.canon/hardening/"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-1763",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-01-22T19:47:47.922240Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-01-22T19:47:54.570Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "Canon IJ NW Tool",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8)"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the software."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-549",
"description": "CWE-549: Missing Password Field Masking",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-05-17T00:00:00.000Z",
"orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"shortName": "Canon"
},
"references": [
{
"url": "https://psirt.canon/advisory-information/cp2023-002/"
},
{
"url": "https://psirt.canon/hardening/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"assignerShortName": "Canon",
"cveId": "CVE-2023-1763",
"datePublished": "2023-05-17T00:00:00.000Z",
"dateReserved": "2023-03-31T00:00:00.000Z",
"dateUpdated": "2025-01-22T19:47:54.570Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2022-38765 (GCVE-0-2022-38765)
Vulnerability from nvd – Published: 2022-12-08 00:00 – Updated: 2025-04-23 15:48
VLAI
EPSS
VEX
Summary
Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is able to gain unauthorized access to imaging records by tampering with the vitrea-view/studies/search patientId parameter.
Severity
6.5 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-04-23 15:47 UTC
CWE
- n/a
- CWE-639 - Authorization Bypass Through User-Controlled Key
Assigner
References
1 reference
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T11:02:14.515Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2022-38765",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-04-23T15:47:46.103729Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "CWE-639 Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-04-23T15:48:17.869Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is able to gain unauthorized access to imaging records by tampering with the vitrea-view/studies/search patientId parameter."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2022-12-08T00:00:00.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"url": "https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2022-38765",
"datePublished": "2022-12-08T00:00:00.000Z",
"dateReserved": "2022-08-25T00:00:00.000Z",
"dateUpdated": "2025-04-23T15:48:17.869Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2022-37461 (GCVE-0-2022-37461)
Vulnerability from nvd – Published: 2022-09-30 13:26 – Updated: 2025-05-20 19:21
VLAI
EPSS
VEX
Summary
Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the input after the error subdirectory to the /vitrea-view/error/ subdirectory, or the (2) groupID, (3) offset, or (4) limit parameter to an Administrative Panel (Group and Users) page. There is a risk of an attacker retrieving patient information.
Severity
6.1 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-05-20 19:20 UTC
CWE
- n/a
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.vitalimages.com/vitrea-vision/vitrea-view/ | x_refsource_MISC |
| https://www.trustwave.com/en-us/resources/securit… | x_refsource_MISC |
| https://www.vitalimages.com/customer-success-supp… | x_refsource_CONFIRM |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T10:29:21.038Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://www.vitalimages.com/vitrea-vision/vitrea-view/"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=30693"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2022-37461",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-05-20T19:20:54.108652Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-05-20T19:21:22.569Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the input after the error subdirectory to the /vitrea-view/error/ subdirectory, or the (2) groupID, (3) offset, or (4) limit parameter to an Administrative Panel (Group and Users) page. There is a risk of an attacker retrieving patient information."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2022-09-30T23:03:53.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"tags": [
"x_refsource_MISC"
],
"url": "https://www.vitalimages.com/vitrea-vision/vitrea-view/"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=30693"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2022-37461",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the input after the error subdirectory to the /vitrea-view/error/ subdirectory, or the (2) groupID, (3) offset, or (4) limit parameter to an Administrative Panel (Group and Users) page. There is a risk of an attacker retrieving patient information."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://www.vitalimages.com/vitrea-vision/vitrea-view/",
"refsource": "MISC",
"url": "https://www.vitalimages.com/vitrea-vision/vitrea-view/"
},
{
"name": "https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=30693",
"refsource": "MISC",
"url": "https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=30693"
},
{
"name": "https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/",
"refsource": "CONFIRM",
"url": "https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2022-37461",
"datePublished": "2022-09-30T13:26:37.000Z",
"dateReserved": "2022-08-07T00:00:00.000Z",
"dateUpdated": "2025-05-20T19:21:22.569Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2022-26111 (GCVE-0-2022-26111)
Vulnerability from nvd – Published: 2022-04-25 14:38 – Updated: 2024-08-03 04:56
VLAI
EPSS
VEX
Summary
The BeanShell components of IRISNext through 9.8.28 allow execution of arbitrary commands on the target server by creating a custom search (or editing an existing/predefined search) of the documents. The search components permit adding BeanShell expressions that result in Remote Code Execution in the context of the IRISNext application user, running on the web server.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://varsnext.iriscorporate.com/ | x_refsource_MISC |
| https://github.com/post-cyberlabs/CVE-Advisory/bl… | x_refsource_MISC |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T04:56:37.823Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://varsnext.iriscorporate.com/"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2022-26111.pdf"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The BeanShell components of IRISNext through 9.8.28 allow execution of arbitrary commands on the target server by creating a custom search (or editing an existing/predefined search) of the documents. The search components permit adding BeanShell expressions that result in Remote Code Execution in the context of the IRISNext application user, running on the web server."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2022-04-25T14:38:12.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"tags": [
"x_refsource_MISC"
],
"url": "https://varsnext.iriscorporate.com/"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2022-26111.pdf"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2022-26111",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "The BeanShell components of IRISNext through 9.8.28 allow execution of arbitrary commands on the target server by creating a custom search (or editing an existing/predefined search) of the documents. The search components permit adding BeanShell expressions that result in Remote Code Execution in the context of the IRISNext application user, running on the web server."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://varsnext.iriscorporate.com/",
"refsource": "MISC",
"url": "https://varsnext.iriscorporate.com/"
},
{
"name": "https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2022-26111.pdf",
"refsource": "MISC",
"url": "https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2022-26111.pdf"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2022-26111",
"datePublished": "2022-04-25T14:38:12.000Z",
"dateReserved": "2022-02-25T00:00:00.000Z",
"dateUpdated": "2024-08-03T04:56:37.823Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2022-26320 (GCVE-0-2022-26320)
Vulnerability from nvd – Published: 2022-03-14 17:28 – Updated: 2024-10-07 16:04
VLAI
EPSS
VEX
Summary
The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with Fermat's factorization method. This allows efficient calculation of private RSA keys from the public key of a TLS certificate.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
6 references
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T05:03:32.548Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://global.canon/en/support/security/index.html"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://fermatattack.secvuln.info"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "https://www.fujifilm.com/fbglobal/eng/company/news/notice/2022/0302_rsakey_announce.html"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://safezoneswupdate.com"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with Fermat\u0027s factorization method. This allows efficient calculation of private RSA keys from the public key of a TLS certificate."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-10-07T16:04:03.893Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"url": "https://global.canon/en/support/security/index.html"
},
{
"url": "https://fermatattack.secvuln.info"
},
{
"url": "https://www.fujifilm.com/fbglobal/eng/company/news/notice/2022/0302_rsakey_announce.html"
},
{
"url": "https://www.rambus.com/security/response-center/advisories/rmbs-2021-01/"
},
{
"url": "https://web.archive.org/web/20220922042721/https://safezoneswupdate.com/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2022-26320",
"datePublished": "2022-03-14T17:28:04.000Z",
"dateReserved": "2022-02-28T00:00:00.000Z",
"dateUpdated": "2024-10-07T16:04:03.893Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2021-20877 (GCVE-0-2021-20877)
Vulnerability from nvd – Published: 2022-02-08 10:30 – Updated: 2024-08-03 17:53
VLAI
EPSS
VEX
Summary
Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series (MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series (LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS (LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER (2206IF, 2204N, and 2204F) sold in Europe) allows remote attackers to inject an arbitrary script via unspecified vectors.
Severity
No CVSS data available.
CWE
- Cross-site scripting
Assigner
References
5 references
| URL | Tags |
|---|---|
| https://cweb.canon.jp/e-support/info/211221xss.html | x_refsource_MISC |
| https://www.usa.canon.com/internet/portal/us/home… | x_refsource_MISC |
| https://www.canon-europe.com/support/product-secu… | x_refsource_MISC |
| https://jvn.jp/en/jp/JVN64806328/index.html | x_refsource_MISC |
| https://jvn.jp/jp/JVN64806328/index.html | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Canon | Canon laser printers and small office multifunctional printers |
Affected:
LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series(MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series(LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS(LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER(2206IF, 2204N, and 2204F) sold in Europe
|
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T17:53:23.123Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://cweb.canon.jp/e-support/info/211221xss.html"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/Service-Notice-Canon-Laser-Printer-and-Small-Office-Multifunctional-Printer-related-to-cross-site-scripting"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://www.canon-europe.com/support/product-security-latest-news/"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://jvn.jp/en/jp/JVN64806328/index.html"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://jvn.jp/jp/JVN64806328/index.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "Canon laser printers and small office multifunctional printers",
"vendor": "Canon",
"versions": [
{
"status": "affected",
"version": "LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series(MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series(LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS(LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER(2206IF, 2204N, and 2204F) sold in Europe"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series (MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series (LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS (LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER (2206IF, 2204N, and 2204F) sold in Europe) allows remote attackers to inject an arbitrary script via unspecified vectors."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Cross-site scripting",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2022-02-08T10:30:31.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"tags": [
"x_refsource_MISC"
],
"url": "https://cweb.canon.jp/e-support/info/211221xss.html"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/Service-Notice-Canon-Laser-Printer-and-Small-Office-Multifunctional-Printer-related-to-cross-site-scripting"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://www.canon-europe.com/support/product-security-latest-news/"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://jvn.jp/en/jp/JVN64806328/index.html"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://jvn.jp/jp/JVN64806328/index.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2021-20877",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "Canon laser printers and small office multifunctional printers",
"version": {
"version_data": [
{
"version_value": "LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series(MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series(LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS(LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER(2206IF, 2204N, and 2204F) sold in Europe"
}
]
}
}
]
},
"vendor_name": "Canon"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series (MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series (LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS (LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER (2206IF, 2204N, and 2204F) sold in Europe) allows remote attackers to inject an arbitrary script via unspecified vectors."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Cross-site scripting"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://cweb.canon.jp/e-support/info/211221xss.html",
"refsource": "MISC",
"url": "https://cweb.canon.jp/e-support/info/211221xss.html"
},
{
"name": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/Service-Notice-Canon-Laser-Printer-and-Small-Office-Multifunctional-Printer-related-to-cross-site-scripting",
"refsource": "MISC",
"url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/Service-Notice-Canon-Laser-Printer-and-Small-Office-Multifunctional-Printer-related-to-cross-site-scripting"
},
{
"name": "https://www.canon-europe.com/support/product-security-latest-news/",
"refsource": "MISC",
"url": "https://www.canon-europe.com/support/product-security-latest-news/"
},
{
"name": "https://jvn.jp/en/jp/JVN64806328/index.html",
"refsource": "MISC",
"url": "https://jvn.jp/en/jp/JVN64806328/index.html"
},
{
"name": "https://jvn.jp/jp/JVN64806328/index.html",
"refsource": "MISC",
"url": "https://jvn.jp/jp/JVN64806328/index.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2021-20877",
"datePublished": "2022-02-08T10:30:31.000Z",
"dateReserved": "2020-12-17T00:00:00.000Z",
"dateUpdated": "2024-08-03T17:53:23.123Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2021-38154 (GCVE-0-2021-38154)
Vulnerability from nvd – Published: 2021-08-29 04:59 – Updated: 2024-08-04 01:37Summary
Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, allow remote attackers to modify an e-mail address setting, and thus cause the device to send sensitive information through e-mail to the attacker. For example, an incoming FAX may be sent through e-mail to the attacker. This occurs when a PIN is not required for General User Mode, as exploited in the wild in August 2021.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://www.usa.canon.com/internet/portal/us/home… | x_refsource_MISC |
| https://protocolpolice.nl/CVE-2021-38154_Protocol… | x_refsource_MISC |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-04T01:37:16.022Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://protocolpolice.nl/CVE-2021-38154_Protocol_Police_Catwalk_Alert"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, allow remote attackers to modify an e-mail address setting, and thus cause the device to send sensitive information through e-mail to the attacker. For example, an incoming FAX may be sent through e-mail to the attacker. This occurs when a PIN is not required for General User Mode, as exploited in the wild in August 2021."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2021-08-29T04:59:18.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"tags": [
"x_refsource_MISC"
],
"url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://protocolpolice.nl/CVE-2021-38154_Protocol_Police_Catwalk_Alert"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2021-38154",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, allow remote attackers to modify an e-mail address setting, and thus cause the device to send sensitive information through e-mail to the attacker. For example, an incoming FAX may be sent through e-mail to the attacker. This occurs when a PIN is not required for General User Mode, as exploited in the wild in August 2021."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories",
"refsource": "MISC",
"url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories"
},
{
"name": "https://protocolpolice.nl/CVE-2021-38154_Protocol_Police_Catwalk_Alert",
"refsource": "MISC",
"url": "https://protocolpolice.nl/CVE-2021-38154_Protocol_Police_Catwalk_Alert"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2021-38154",
"datePublished": "2021-08-29T04:59:18.000Z",
"dateReserved": "2021-08-06T00:00:00.000Z",
"dateUpdated": "2024-08-04T01:37:16.022Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2021-39368 (GCVE-0-2021-39368)
Vulnerability from nvd – Published: 2021-08-22 23:21 – Updated: 2024-08-04 02:06
VLAI
EPSS
VEX
Summary
Canon Oce Print Exec Workgroup 1.3.2 allows XSS via the lang parameter.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://github.com/IthacaLabs/Canon/tree/main/OCE… | x_refsource_MISC |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-04T02:06:42.488Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/IthacaLabs/Canon/tree/main/OCE_Print_Exec_Workgroup_Version_1_3_2/XSS_HTMLi"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Canon Oce Print Exec Workgroup 1.3.2 allows XSS via the lang parameter."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2021-08-22T23:21:13.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/IthacaLabs/Canon/tree/main/OCE_Print_Exec_Workgroup_Version_1_3_2/XSS_HTMLi"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2021-39368",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Canon Oce Print Exec Workgroup 1.3.2 allows XSS via the lang parameter."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://github.com/IthacaLabs/Canon/tree/main/OCE_Print_Exec_Workgroup_Version_1_3_2/XSS_HTMLi",
"refsource": "MISC",
"url": "https://github.com/IthacaLabs/Canon/tree/main/OCE_Print_Exec_Workgroup_Version_1_3_2/XSS_HTMLi"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2021-39368",
"datePublished": "2021-08-22T23:21:13.000Z",
"dateReserved": "2021-08-22T00:00:00.000Z",
"dateUpdated": "2024-08-04T02:06:42.488Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2021-39367 (GCVE-0-2021-39367)
Vulnerability from nvd – Published: 2021-08-22 23:21 – Updated: 2024-08-04 02:06
VLAI
EPSS
VEX
Summary
Canon Oce Print Exec Workgroup 1.3.2 allows Host header injection.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://github.com/IthacaLabs/Canon/tree/main/OCE… | x_refsource_MISC |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-04T02:06:42.493Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/IthacaLabs/Canon/tree/main/OCE_Print_Exec_Workgroup_Version_1_3_2/HHI"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Canon Oce Print Exec Workgroup 1.3.2 allows Host header injection."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2021-08-22T23:21:03.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/IthacaLabs/Canon/tree/main/OCE_Print_Exec_Workgroup_Version_1_3_2/HHI"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2021-39367",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Canon Oce Print Exec Workgroup 1.3.2 allows Host header injection."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://github.com/IthacaLabs/Canon/tree/main/OCE_Print_Exec_Workgroup_Version_1_3_2/HHI",
"refsource": "MISC",
"url": "https://github.com/IthacaLabs/Canon/tree/main/OCE_Print_Exec_Workgroup_Version_1_3_2/HHI"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2021-39367",
"datePublished": "2021-08-22T23:21:03.000Z",
"dateReserved": "2021-08-22T00:00:00.000Z",
"dateUpdated": "2024-08-04T02:06:42.493Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2026-9262 (GCVE-0-2026-9262)
Vulnerability from cvelistv5 – Published: 2026-06-15 23:40 – Updated: 2026-06-16 15:01
VLAI
EPSS
VEX
Summary
Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-06-16 15:01 UTC
CWE
- CWE-1188 - Initialization of a resource with an insecure default
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://psirt.canon/advisory-information/cp2026-005/ | vendor-advisory |
| https://canon.jp/support/support-info/260615vulne… | vendor-advisory |
| https://www.usa.canon.com/about-us/to-our-custome… | vendor-advisory |
| https://www.canon-europe.com/support/product-security/ | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Canon Inc. | EOS Network Setting Tool for Windows |
Affected:
1.5.0 or earlier
|
|
| Canon Inc. | EOS Network Setting Tool for macOS |
Affected:
1.5.0 or earlier
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-9262",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-16T15:01:20.368197Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-16T15:01:31.260Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "EOS Network Setting Tool for Windows",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "1.5.0 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "EOS Network Setting Tool for macOS",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "1.5.0 or earlier"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "This issue was discovered by Ryan Hausknecht (@haus3c)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
}
],
"value": "Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1188",
"description": "CWE-1188 Initialization of a resource with an insecure default",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-06-15T23:40:15.216Z",
"orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"shortName": "Canon"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://psirt.canon/advisory-information/cp2026-005/"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://canon.jp/support/support-info/260615vulnerability-response"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.usa.canon.com/about-us/to-our-customers/cpa2026-005-vulnerability-remediation-for-eos-network-setting-tool"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.canon-europe.com/support/product-security/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"x_generator": {
"engine": "Vulnogram 1.0.2"
}
}
},
"cveMetadata": {
"assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"assignerShortName": "Canon",
"cveId": "CVE-2026-9262",
"datePublished": "2026-06-15T23:40:15.216Z",
"dateReserved": "2026-05-21T23:14:55.152Z",
"dateUpdated": "2026-06-16T15:01:31.260Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-9261 (GCVE-0-2026-9261)
Vulnerability from cvelistv5 – Published: 2026-06-15 23:39 – Updated: 2026-06-18 03:55
VLAI
EPSS
VEX
Summary
Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-06-17 00:00 UTC
CWE
- CWE-327 - Use of a Broken or Risky Cryptographic Algorithm
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://psirt.canon/advisory-information/cp2026-005/ | vendor-advisory |
| https://canon.jp/support/support-info/260615vulne… | vendor-advisory |
| https://www.usa.canon.com/about-us/to-our-custome… | vendor-advisory |
| https://www.canon-europe.com/support/product-security/ | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Canon Inc. | EOS Network Setting Tool for Windows |
Affected:
1.5.0 or earlier
|
|
| Canon Inc. | EOS Network Setting Tool for macOS |
Affected:
1.5.0 or earlier
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-9261",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-17T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-18T03:55:38.801Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "EOS Network Setting Tool for Windows",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "1.5.0 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "EOS Network Setting Tool for macOS",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "1.5.0 or earlier"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "This issue was discovered by Ryan Hausknecht (@haus3c)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
}
],
"value": "Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "HIGH",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.6,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-327",
"description": "CWE-327: Use of a Broken or Risky Cryptographic Algorithm",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-06-15T23:39:23.700Z",
"orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"shortName": "Canon"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://psirt.canon/advisory-information/cp2026-005/"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://canon.jp/support/support-info/260615vulnerability-response"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.usa.canon.com/about-us/to-our-customers/cpa2026-005-vulnerability-remediation-for-eos-network-setting-tool"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.canon-europe.com/support/product-security/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"x_generator": {
"engine": "Vulnogram 1.0.2"
}
}
},
"cveMetadata": {
"assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"assignerShortName": "Canon",
"cveId": "CVE-2026-9261",
"datePublished": "2026-06-15T23:39:23.700Z",
"dateReserved": "2026-05-21T23:14:53.345Z",
"dateUpdated": "2026-06-18T03:55:38.801Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-9260 (GCVE-0-2026-9260)
Vulnerability from cvelistv5 – Published: 2026-06-15 23:38 – Updated: 2026-06-16 12:41
VLAI
EPSS
VEX
Summary
Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Severity
6.2 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-06-16 12:41 UTC
CWE
- CWE-321 - Use of hard-coded cryptographic key
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://psirt.canon/advisory-information/cp2026-005/ | vendor-advisory |
| https://canon.jp/support/support-info/260615vulne… | vendor-advisory |
| https://www.usa.canon.com/about-us/to-our-custome… | vendor-advisory |
| https://www.canon-europe.com/support/product-security/ | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Canon Inc. | EOS Network Setting Tool for Windows |
Affected:
1.5.0 or earlier
|
|
| Canon Inc. | EOS Network Setting Tool for macOS |
Affected:
1.5.0 or earlier
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-9260",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-16T12:41:33.426171Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-16T12:41:43.181Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "EOS Network Setting Tool for Windows",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "1.5.0 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "EOS Network Setting Tool for macOS",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "1.5.0 or earlier"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "This issue was discovered by Ryan Hausknecht (@haus3c)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
}
],
"value": "Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "LOCAL",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "NONE",
"baseScore": 6.2,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-321",
"description": "CWE-321 Use of hard-coded cryptographic key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-06-15T23:38:29.951Z",
"orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"shortName": "Canon"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://psirt.canon/advisory-information/cp2026-005/"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://canon.jp/support/support-info/260615vulnerability-response"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.usa.canon.com/about-us/to-our-customers/cpa2026-005-vulnerability-remediation-for-eos-network-setting-tool"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.canon-europe.com/support/product-security/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"x_generator": {
"engine": "Vulnogram 1.0.2"
}
}
},
"cveMetadata": {
"assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"assignerShortName": "Canon",
"cveId": "CVE-2026-9260",
"datePublished": "2026-06-15T23:38:29.951Z",
"dateReserved": "2026-05-21T23:14:51.893Z",
"dateUpdated": "2026-06-16T12:41:43.181Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-9259 (GCVE-0-2026-9259)
Vulnerability from cvelistv5 – Published: 2026-06-15 23:36 – Updated: 2026-06-16 12:43
VLAI
EPSS
VEX
Summary
Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-06-16 12:43 UTC
CWE
- CWE-295 - Improper certificate validation
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://psirt.canon/advisory-information/cp2026-005/ | vendor-advisory |
| https://canon.jp/support/support-info/260615vulne… | vendor-advisory |
| https://www.usa.canon.com/about-us/to-our-custome… | vendor-advisory |
| https://www.canon-europe.com/support/product-security/ | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Canon Inc. | EOS Network Setting Tool for Windows |
Affected:
1.5.0 or earlier
|
|
| Canon Inc. | EOS Network Setting Tool for macOS |
Affected:
1.5.0 or earlier
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-9259",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-16T12:43:13.289990Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-16T12:43:21.760Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "EOS Network Setting Tool for Windows",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "1.5.0 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "EOS Network Setting Tool for macOS",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "1.5.0 or earlier"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "This issue was discovered by Ryan Hausknecht (@haus3c)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
}
],
"value": "Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-295",
"description": "CWE-295 Improper certificate validation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-06-15T23:36:28.761Z",
"orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"shortName": "Canon"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://psirt.canon/advisory-information/cp2026-005/"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://canon.jp/support/support-info/260615vulnerability-response"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.usa.canon.com/about-us/to-our-customers/cpa2026-005-vulnerability-remediation-for-eos-network-setting-tool"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.canon-europe.com/support/product-security/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"x_generator": {
"engine": "Vulnogram 1.0.2"
}
}
},
"cveMetadata": {
"assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"assignerShortName": "Canon",
"cveId": "CVE-2026-9259",
"datePublished": "2026-06-15T23:36:28.761Z",
"dateReserved": "2026-05-21T23:14:50.204Z",
"dateUpdated": "2026-06-16T12:43:21.760Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-9258 (GCVE-0-2026-9258)
Vulnerability from cvelistv5 – Published: 2026-06-15 23:35 – Updated: 2026-06-16 12:47
VLAI
EPSS
VEX
Summary
Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-06-16 12:47 UTC
CWE
- CWE-295 - Improper certificate validation
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://psirt.canon/advisory-information/cp2026-005/ | vendor-advisory |
| https://canon.jp/support/support-info/260615vulne… | vendor-advisory |
| https://www.usa.canon.com/about-us/to-our-custome… | vendor-advisory |
| https://www.canon-europe.com/support/product-security/ | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Canon Inc. | EOS Network Setting Tool for Windows |
Affected:
1.5.0 or earlier
|
|
| Canon Inc. | EOS Network Setting Tool for macOS |
Affected:
1.5.0 or earlier
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-9258",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-16T12:47:09.464807Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-16T12:47:23.858Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "EOS Network Setting Tool for Windows",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "1.5.0 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "EOS Network Setting Tool for macOS",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "1.5.0 or earlier"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "This issue was discovered by Ryan Hausknecht (@haus3c)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
}
],
"value": "Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-295",
"description": "CWE-295 Improper certificate validation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-06-15T23:35:41.442Z",
"orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"shortName": "Canon"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://psirt.canon/advisory-information/cp2026-005/"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://canon.jp/support/support-info/260615vulnerability-response"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.usa.canon.com/about-us/to-our-customers/cpa2026-005-vulnerability-remediation-for-eos-network-setting-tool"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.canon-europe.com/support/product-security/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"x_generator": {
"engine": "Vulnogram 1.0.2"
}
}
},
"cveMetadata": {
"assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"assignerShortName": "Canon",
"cveId": "CVE-2026-9258",
"datePublished": "2026-06-15T23:35:41.442Z",
"dateReserved": "2026-05-21T23:14:48.638Z",
"dateUpdated": "2026-06-16T12:47:23.858Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2024-2184 (GCVE-0-2024-2184)
Vulnerability from cvelistv5 – Published: 2024-03-11 00:26 – Updated: 2024-08-28 20:24
VLAI
EPSS
VEX
Summary
Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF740C Series/Satera MF640C Series/Satera LBP660C Series/Satera LBP620C Series firmware v12.07 and earlier, and Satera MF750C Series/Satera LBP670C Series firmware v03.09 and earlier sold in Japan.Color imageCLASS MF740C Series/Color imageCLASS MF640C Series/Color imageCLASS X MF1127C/Color imageCLASS LBP664Cdw/Color imageCLASS LBP622Cdw/Color imageCLASS X LBP1127C firmware v12.07 and earlier, and Color imageCLASS MF750C Series/Color imageCLASS X MF1333C/Color imageCLASS LBP674Cdw/Color imageCLASS X LBP1333C firmware v03.09 and earlier sold in US.i-SENSYS MF740C Series/i-SENSYS MF640C Series/C1127i Series/i-SENSYS LBP660C Series/i-SENSYS LBP620C Series/C1127P firmware v12.07 and earlier, and i-SENSYS MF750C Series/C1333i Series/i-SENSYS LBP673Cdw/C1333P firmware v03.09 and earlier sold in Europe.
Severity
9.8 (Critical)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-03-11 15:11 UTC
CWE
- CWE-787 - Out-of-bounds Write
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://psirt.canon/advisory-information/cp2024-002/ | vendor-advisory |
Impacted products
52 products
| Vendor | Product | Version | |
|---|---|---|---|
| Canon Inc. | Color imageCLASS MF740C Series |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | Color imageCLASS MF640C Series |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | i-SENSYS MF740C Series |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | i-SENSYS MF640C Series |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | Satera MF740C Series |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | Satera MF640C Series |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | Color imageCLASS X MF1127C |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | C1127i Series |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | Color imageCLASS LBP664Cdw |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | Color imageCLASS LBP622Cdw |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | i-SENSYS LBP660C Series |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | i-SENSYS LBP620C Series |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | Satera LBP660C Series |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | Satera LBP620C Series |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | Color imageCLASS X LBP1127C |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | C1127P |
Affected:
v12.07 and earlier
|
|
| Canon Inc. | Color imageCLASS MF750C Series |
Affected:
v03.09 and earlier
|
|
| Canon Inc. | i-SENSYS MF750C Series |
Affected:
v03.09 and earlier
|
|
| Canon Inc. | Satera MF750C Series |
Affected:
v03.09 and earlier
|
|
| Canon Inc. | Color imageCLASS X MF1333C |
Affected:
v03.09 and earlier
|
|
| Canon Inc. | C1333i Series |
Affected:
v03.09 and earlier
|
|
| Canon Inc. | Color imageCLASS LBP674Cdw |
Affected:
v03.09 and earlier
|
|
| Canon Inc. | i-SENSYS LBP673Cdw |
Affected:
v03.09 and earlier
|
|
| Canon Inc. | Satera LBP670C Series |
Affected:
v03.09 and earlier
|
|
| Canon Inc. | Color imageCLASS X LBP1333C |
Affected:
v03.09 and earlier
|
|
| Canon Inc. | C1333P |
Affected:
v03.09 and earlier
|
|
| canon | color_imageclass_mf740c_series |
Affected:
0 , ≤ 12..07
(custom)
cpe:2.3:h:canon:color_imageclass_mf740c_series:*:*:*:*:*:*:*:* |
|
| canon | color_imageclass_mf640c_series |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:color_imageclass_mf640c_series:*:*:*:*:*:*:*:* |
|
| canon | i-sensys_mf740c_series |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:i-sensys_mf740c_series:*:*:*:*:*:*:*:* |
|
| canon | i-sensys_mf640c_series |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:i-sensys_mf640c_series:*:*:*:*:*:*:*:* |
|
| canon | satera_mf740c_series |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:satera_mf740c_series:*:*:*:*:*:*:*:* |
|
| canon | color_imageclass_x_mf1127c |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:color_imageclass_x_mf1127c:*:*:*:*:*:*:*:* |
|
| canon | color_imageclass_lbp664cdw |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:color_imageclass_lbp664cdw:*:*:*:*:*:*:*:* |
|
| canon | c1127i_series |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:c1127i_series:*:*:*:*:*:*:*:* |
|
| canon | color_imageclass_lbp622cdw |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:color_imageclass_lbp622cdw:*:*:*:*:*:*:*:* |
|
| canon | i-sensys_lbp660c_series |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:i-sensys_lbp660c_series:*:*:*:*:*:*:*:* |
|
| canon | i-sensys_lbp620c_series |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:i-sensys_lbp620c_series:*:*:*:*:*:*:*:* |
|
| canon | i-sensys_mf750c_series |
Affected:
0 , ≤ 03.09
(custom)
cpe:2.3:h:canon:i-sensys_mf750c_series:*:*:*:*:*:*:*:* |
|
| canon | color_imageclass_x_lbp1333c |
Affected:
0 , ≤ 03.09
(custom)
cpe:2.3:h:canon:color_imageclass_x_lbp1333c:*:*:*:*:*:*:*:* |
|
| canon | i-sensys_lbp673cdw |
Affected:
0 , ≤ 03.09
(custom)
cpe:2.3:h:canon:i-sensys_lbp673cdw:*:*:*:*:*:*:*:* |
|
| canon | satera_lbp670c_series |
Affected:
0 , ≤ 03.09
(custom)
cpe:2.3:h:canon:satera_lbp670c_series:*:*:*:*:*:*:*:* |
|
| canon | c1333p |
Affected:
0 , ≤ 03.09
(custom)
cpe:2.3:h:canon:c1333p:*:*:*:*:*:*:*:* |
|
| canon | satera_mf640c_series |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:satera_mf640c_series:*:*:*:*:*:*:*:* |
|
| canon | satera_lbp620c_series |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:satera_lbp620c_series:*:*:*:*:*:*:*:* |
|
| canon | satera_lbp660c_series |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:satera_lbp660c_series:*:*:*:*:*:*:*:* |
|
| canon | color_imageclass_x_lbp1127c |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:color_imageclass_x_lbp1127c:*:*:*:*:*:*:*:* |
|
| canon | color_imageclass_mf750c_series |
Affected:
0 , ≤ 03.09
(custom)
cpe:2.3:h:canon:color_imageclass_mf750c_series:*:*:*:*:*:*:*:* |
|
| canon | c1127p |
Affected:
0 , ≤ 12.07
(custom)
cpe:2.3:h:canon:c1127p:*:*:*:*:*:*:*:* |
|
| canon | satera_mf750c_series |
Affected:
0 , ≤ 03.09
(custom)
cpe:2.3:h:canon:satera_mf750c_series:*:*:*:*:*:*:*:* |
|
| canon | color_imageclass_x_mf1333c |
Affected:
0 , ≤ 03.09
(custom)
cpe:2.3:h:canon:color_imageclass_x_mf1333c:*:*:*:*:*:*:*:* |
|
| canon | c1333i_series |
Affected:
0 , ≤ 03.09
(custom)
cpe:2.3:h:canon:c1333i_series:*:*:*:*:*:*:*:* |
|
| canon | color_imageclass_lbp674cdw |
Affected:
0 , ≤ 03.09
(custom)
cpe:2.3:h:canon:color_imageclass_lbp674cdw:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-01T19:03:39.266Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://psirt.canon/advisory-information/cp2024-002/"
}
],
"title": "CVE Program Container"
},
{
"affected": [
{
"cpes": [
"cpe:2.3:h:canon:color_imageclass_mf740c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "color_imageclass_mf740c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12..07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:color_imageclass_mf640c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "color_imageclass_mf640c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:i-sensys_mf740c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "i-sensys_mf740c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:i-sensys_mf640c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "i-sensys_mf640c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:satera_mf740c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "satera_mf740c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:color_imageclass_x_mf1127c:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "color_imageclass_x_mf1127c",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:color_imageclass_lbp664cdw:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "color_imageclass_lbp664cdw",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:c1127i_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "c1127i_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:color_imageclass_lbp622cdw:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "color_imageclass_lbp622cdw",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:i-sensys_lbp660c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "i-sensys_lbp660c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:i-sensys_lbp620c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "i-sensys_lbp620c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:i-sensys_mf750c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "i-sensys_mf750c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "03.09",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:color_imageclass_x_lbp1333c:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "color_imageclass_x_lbp1333c",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "03.09",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:i-sensys_lbp673cdw:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "i-sensys_lbp673cdw",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "03.09",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:satera_lbp670c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "satera_lbp670c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "03.09",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:c1333p:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "c1333p",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "03.09",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:satera_mf640c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "satera_mf640c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:satera_lbp620c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "satera_lbp620c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:satera_lbp660c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "satera_lbp660c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:color_imageclass_x_lbp1127c:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "color_imageclass_x_lbp1127c",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:color_imageclass_mf750c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "color_imageclass_mf750c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "03.09",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:c1127p:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "c1127p",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "12.07",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:satera_mf750c_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "satera_mf750c_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "03.09",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:color_imageclass_x_mf1333c:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "color_imageclass_x_mf1333c",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "03.09",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:c1333i_series:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "c1333i_series",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "03.09",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:canon:color_imageclass_lbp674cdw:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "color_imageclass_lbp674cdw",
"vendor": "canon",
"versions": [
{
"lessThanOrEqual": "03.09",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-2184",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-03-11T15:11:33.695685Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-08-28T20:24:54.597Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "Color imageCLASS MF740C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "Color imageCLASS MF640C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "i-SENSYS MF740C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "i-SENSYS MF640C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "Satera MF740C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "Satera MF640C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "Color imageCLASS X MF1127C",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "C1127i Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "Color imageCLASS LBP664Cdw",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "Color imageCLASS LBP622Cdw",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "i-SENSYS LBP660C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "i-SENSYS LBP620C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "Satera LBP660C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "Satera LBP620C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "Color imageCLASS X LBP1127C",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "C1127P",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v12.07 and earlier"
}
]
},
{
"product": "Color imageCLASS MF750C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v03.09 and earlier"
}
]
},
{
"product": "i-SENSYS MF750C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v03.09 and earlier"
}
]
},
{
"product": "Satera MF750C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v03.09 and earlier"
}
]
},
{
"product": "Color imageCLASS X MF1333C",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v03.09 and earlier"
}
]
},
{
"product": "C1333i Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v03.09 and earlier"
}
]
},
{
"product": "Color imageCLASS LBP674Cdw",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v03.09 and earlier"
}
]
},
{
"product": "i-SENSYS LBP673Cdw",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v03.09 and earlier"
}
]
},
{
"product": "Satera LBP670C Series",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v03.09 and earlier"
}
]
},
{
"product": "Color imageCLASS X LBP1333C",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v03.09 and earlier"
}
]
},
{
"product": "C1333P",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "v03.09 and earlier"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eBuffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF740C Series/Satera MF640C Series/Satera LBP660C Series/Satera LBP620C Series firmware v12.07 and earlier, and Satera MF750C Series/Satera LBP670C Series firmware v03.09 and earlier sold in Japan.Color imageCLASS MF740C Series/Color imageCLASS MF640C Series/Color imageCLASS X MF1127C/Color imageCLASS LBP664Cdw/Color imageCLASS LBP622Cdw/Color imageCLASS X LBP1127C firmware v12.07 and earlier, and Color imageCLASS MF750C Series/Color imageCLASS X MF1333C/Color imageCLASS LBP674Cdw/Color imageCLASS X LBP1333C firmware v03.09 and earlier sold in US.i-SENSYS MF740C Series/i-SENSYS MF640C Series/C1127i Series/i-SENSYS LBP660C Series/i-SENSYS LBP620C Series/C1127P firmware v12.07 and earlier, and i-SENSYS MF750C Series/C1333i Series/i-SENSYS LBP673Cdw/C1333P firmware v03.09 and earlier sold in Europe.\u003c/p\u003e"
}
],
"value": "Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF740C Series/Satera MF640C Series/Satera LBP660C Series/Satera LBP620C Series firmware v12.07 and earlier, and Satera MF750C Series/Satera LBP670C Series firmware v03.09 and earlier sold in Japan.Color imageCLASS MF740C Series/Color imageCLASS MF640C Series/Color imageCLASS X MF1127C/Color imageCLASS LBP664Cdw/Color imageCLASS LBP622Cdw/Color imageCLASS X LBP1127C firmware v12.07 and earlier, and Color imageCLASS MF750C Series/Color imageCLASS X MF1333C/Color imageCLASS LBP674Cdw/Color imageCLASS X LBP1333C firmware v03.09 and earlier sold in US.i-SENSYS MF740C Series/i-SENSYS MF640C Series/C1127i Series/i-SENSYS LBP660C Series/i-SENSYS LBP620C Series/C1127P firmware v12.07 and earlier, and i-SENSYS MF750C Series/C1333i Series/i-SENSYS LBP673Cdw/C1333P firmware v03.09 and earlier sold in Europe.\n\n"
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-787",
"description": "CWE-787: Out-of-bounds Write",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-03-11T00:26:02.346Z",
"orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"shortName": "Canon"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://psirt.canon/advisory-information/cp2024-002/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"assignerShortName": "Canon",
"cveId": "CVE-2024-2184",
"datePublished": "2024-03-11T00:26:02.346Z",
"dateReserved": "2024-03-05T00:44:00.599Z",
"dateUpdated": "2024-08-28T20:24:54.597Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2023-1764 (GCVE-0-2023-1764)
Vulnerability from cvelistv5 – Published: 2023-05-17 00:00 – Updated: 2025-01-22 19:47
VLAI
EPSS
VEX
Summary
Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the communication of the software.
Severity
6.5 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-01-22 19:47 UTC
CWE
- CWE-326 - Inadequate Encryption Strength
Assigner
References
2 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Canon Inc. | Canon IJ NW Tool |
Affected:
Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8)
|
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T05:57:24.994Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://psirt.canon/advisory-information/cp2023-002/"
},
{
"tags": [
"x_transferred"
],
"url": "https://psirt.canon/hardening/"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-1764",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-01-22T19:47:15.479601Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-01-22T19:47:20.955Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "Canon IJ NW Tool",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8)"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the communication of the software."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-326",
"description": "CWE-326: Inadequate Encryption Strength",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-05-17T00:00:00.000Z",
"orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"shortName": "Canon"
},
"references": [
{
"url": "https://psirt.canon/advisory-information/cp2023-002/"
},
{
"url": "https://psirt.canon/hardening/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"assignerShortName": "Canon",
"cveId": "CVE-2023-1764",
"datePublished": "2023-05-17T00:00:00.000Z",
"dateReserved": "2023-03-31T00:00:00.000Z",
"dateUpdated": "2025-01-22T19:47:20.955Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2023-1763 (GCVE-0-2023-1763)
Vulnerability from cvelistv5 – Published: 2023-05-17 00:00 – Updated: 2025-01-22 19:47
VLAI
EPSS
VEX
Summary
Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the software.
Severity
6.5 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-01-22 19:47 UTC
CWE
- CWE-549 - Missing Password Field Masking
Assigner
References
2 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Canon Inc. | Canon IJ NW Tool |
Affected:
Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8)
|
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T05:57:25.055Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://psirt.canon/advisory-information/cp2023-002/"
},
{
"tags": [
"x_transferred"
],
"url": "https://psirt.canon/hardening/"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-1763",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-01-22T19:47:47.922240Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-01-22T19:47:54.570Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "Canon IJ NW Tool",
"vendor": "Canon Inc.",
"versions": [
{
"status": "affected",
"version": "Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8)"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the software."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-549",
"description": "CWE-549: Missing Password Field Masking",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-05-17T00:00:00.000Z",
"orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"shortName": "Canon"
},
"references": [
{
"url": "https://psirt.canon/advisory-information/cp2023-002/"
},
{
"url": "https://psirt.canon/hardening/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"assignerShortName": "Canon",
"cveId": "CVE-2023-1763",
"datePublished": "2023-05-17T00:00:00.000Z",
"dateReserved": "2023-03-31T00:00:00.000Z",
"dateUpdated": "2025-01-22T19:47:54.570Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2022-38765 (GCVE-0-2022-38765)
Vulnerability from cvelistv5 – Published: 2022-12-08 00:00 – Updated: 2025-04-23 15:48
VLAI
EPSS
VEX
Summary
Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is able to gain unauthorized access to imaging records by tampering with the vitrea-view/studies/search patientId parameter.
Severity
6.5 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-04-23 15:47 UTC
CWE
- n/a
- CWE-639 - Authorization Bypass Through User-Controlled Key
Assigner
References
1 reference
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T11:02:14.515Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2022-38765",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-04-23T15:47:46.103729Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "CWE-639 Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-04-23T15:48:17.869Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is able to gain unauthorized access to imaging records by tampering with the vitrea-view/studies/search patientId parameter."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2022-12-08T00:00:00.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"url": "https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2022-38765",
"datePublished": "2022-12-08T00:00:00.000Z",
"dateReserved": "2022-08-25T00:00:00.000Z",
"dateUpdated": "2025-04-23T15:48:17.869Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2022-37461 (GCVE-0-2022-37461)
Vulnerability from cvelistv5 – Published: 2022-09-30 13:26 – Updated: 2025-05-20 19:21
VLAI
EPSS
VEX
Summary
Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the input after the error subdirectory to the /vitrea-view/error/ subdirectory, or the (2) groupID, (3) offset, or (4) limit parameter to an Administrative Panel (Group and Users) page. There is a risk of an attacker retrieving patient information.
Severity
6.1 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-05-20 19:20 UTC
CWE
- n/a
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.vitalimages.com/vitrea-vision/vitrea-view/ | x_refsource_MISC |
| https://www.trustwave.com/en-us/resources/securit… | x_refsource_MISC |
| https://www.vitalimages.com/customer-success-supp… | x_refsource_CONFIRM |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T10:29:21.038Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://www.vitalimages.com/vitrea-vision/vitrea-view/"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=30693"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2022-37461",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-05-20T19:20:54.108652Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-05-20T19:21:22.569Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the input after the error subdirectory to the /vitrea-view/error/ subdirectory, or the (2) groupID, (3) offset, or (4) limit parameter to an Administrative Panel (Group and Users) page. There is a risk of an attacker retrieving patient information."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2022-09-30T23:03:53.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"tags": [
"x_refsource_MISC"
],
"url": "https://www.vitalimages.com/vitrea-vision/vitrea-view/"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=30693"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2022-37461",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the input after the error subdirectory to the /vitrea-view/error/ subdirectory, or the (2) groupID, (3) offset, or (4) limit parameter to an Administrative Panel (Group and Users) page. There is a risk of an attacker retrieving patient information."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://www.vitalimages.com/vitrea-vision/vitrea-view/",
"refsource": "MISC",
"url": "https://www.vitalimages.com/vitrea-vision/vitrea-view/"
},
{
"name": "https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=30693",
"refsource": "MISC",
"url": "https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=30693"
},
{
"name": "https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/",
"refsource": "CONFIRM",
"url": "https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2022-37461",
"datePublished": "2022-09-30T13:26:37.000Z",
"dateReserved": "2022-08-07T00:00:00.000Z",
"dateUpdated": "2025-05-20T19:21:22.569Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2022-26111 (GCVE-0-2022-26111)
Vulnerability from cvelistv5 – Published: 2022-04-25 14:38 – Updated: 2024-08-03 04:56
VLAI
EPSS
VEX
Summary
The BeanShell components of IRISNext through 9.8.28 allow execution of arbitrary commands on the target server by creating a custom search (or editing an existing/predefined search) of the documents. The search components permit adding BeanShell expressions that result in Remote Code Execution in the context of the IRISNext application user, running on the web server.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://varsnext.iriscorporate.com/ | x_refsource_MISC |
| https://github.com/post-cyberlabs/CVE-Advisory/bl… | x_refsource_MISC |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T04:56:37.823Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://varsnext.iriscorporate.com/"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2022-26111.pdf"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The BeanShell components of IRISNext through 9.8.28 allow execution of arbitrary commands on the target server by creating a custom search (or editing an existing/predefined search) of the documents. The search components permit adding BeanShell expressions that result in Remote Code Execution in the context of the IRISNext application user, running on the web server."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2022-04-25T14:38:12.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"tags": [
"x_refsource_MISC"
],
"url": "https://varsnext.iriscorporate.com/"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2022-26111.pdf"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2022-26111",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "The BeanShell components of IRISNext through 9.8.28 allow execution of arbitrary commands on the target server by creating a custom search (or editing an existing/predefined search) of the documents. The search components permit adding BeanShell expressions that result in Remote Code Execution in the context of the IRISNext application user, running on the web server."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://varsnext.iriscorporate.com/",
"refsource": "MISC",
"url": "https://varsnext.iriscorporate.com/"
},
{
"name": "https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2022-26111.pdf",
"refsource": "MISC",
"url": "https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2022-26111.pdf"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2022-26111",
"datePublished": "2022-04-25T14:38:12.000Z",
"dateReserved": "2022-02-25T00:00:00.000Z",
"dateUpdated": "2024-08-03T04:56:37.823Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2022-26320 (GCVE-0-2022-26320)
Vulnerability from cvelistv5 – Published: 2022-03-14 17:28 – Updated: 2024-10-07 16:04
VLAI
EPSS
VEX
Summary
The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with Fermat's factorization method. This allows efficient calculation of private RSA keys from the public key of a TLS certificate.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
6 references
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T05:03:32.548Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://global.canon/en/support/security/index.html"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://fermatattack.secvuln.info"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "https://www.fujifilm.com/fbglobal/eng/company/news/notice/2022/0302_rsakey_announce.html"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://safezoneswupdate.com"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with Fermat\u0027s factorization method. This allows efficient calculation of private RSA keys from the public key of a TLS certificate."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-10-07T16:04:03.893Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"url": "https://global.canon/en/support/security/index.html"
},
{
"url": "https://fermatattack.secvuln.info"
},
{
"url": "https://www.fujifilm.com/fbglobal/eng/company/news/notice/2022/0302_rsakey_announce.html"
},
{
"url": "https://www.rambus.com/security/response-center/advisories/rmbs-2021-01/"
},
{
"url": "https://web.archive.org/web/20220922042721/https://safezoneswupdate.com/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2022-26320",
"datePublished": "2022-03-14T17:28:04.000Z",
"dateReserved": "2022-02-28T00:00:00.000Z",
"dateUpdated": "2024-10-07T16:04:03.893Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2021-20877 (GCVE-0-2021-20877)
Vulnerability from cvelistv5 – Published: 2022-02-08 10:30 – Updated: 2024-08-03 17:53
VLAI
EPSS
VEX
Summary
Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series (MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series (LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS (LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER (2206IF, 2204N, and 2204F) sold in Europe) allows remote attackers to inject an arbitrary script via unspecified vectors.
Severity
No CVSS data available.
CWE
- Cross-site scripting
Assigner
References
5 references
| URL | Tags |
|---|---|
| https://cweb.canon.jp/e-support/info/211221xss.html | x_refsource_MISC |
| https://www.usa.canon.com/internet/portal/us/home… | x_refsource_MISC |
| https://www.canon-europe.com/support/product-secu… | x_refsource_MISC |
| https://jvn.jp/en/jp/JVN64806328/index.html | x_refsource_MISC |
| https://jvn.jp/jp/JVN64806328/index.html | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Canon | Canon laser printers and small office multifunctional printers |
Affected:
LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series(MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series(LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS(LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER(2206IF, 2204N, and 2204F) sold in Europe
|
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T17:53:23.123Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://cweb.canon.jp/e-support/info/211221xss.html"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/Service-Notice-Canon-Laser-Printer-and-Small-Office-Multifunctional-Printer-related-to-cross-site-scripting"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://www.canon-europe.com/support/product-security-latest-news/"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://jvn.jp/en/jp/JVN64806328/index.html"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://jvn.jp/jp/JVN64806328/index.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "Canon laser printers and small office multifunctional printers",
"vendor": "Canon",
"versions": [
{
"status": "affected",
"version": "LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series(MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series(LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS(LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER(2206IF, 2204N, and 2204F) sold in Europe"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series (MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series (LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS (LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER (2206IF, 2204N, and 2204F) sold in Europe) allows remote attackers to inject an arbitrary script via unspecified vectors."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Cross-site scripting",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2022-02-08T10:30:31.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"tags": [
"x_refsource_MISC"
],
"url": "https://cweb.canon.jp/e-support/info/211221xss.html"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/Service-Notice-Canon-Laser-Printer-and-Small-Office-Multifunctional-Printer-related-to-cross-site-scripting"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://www.canon-europe.com/support/product-security-latest-news/"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://jvn.jp/en/jp/JVN64806328/index.html"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://jvn.jp/jp/JVN64806328/index.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2021-20877",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "Canon laser printers and small office multifunctional printers",
"version": {
"version_data": [
{
"version_value": "LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series(MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series(LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS(LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER(2206IF, 2204N, and 2204F) sold in Europe"
}
]
}
}
]
},
"vendor_name": "Canon"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series (MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series (LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS (LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER (2206IF, 2204N, and 2204F) sold in Europe) allows remote attackers to inject an arbitrary script via unspecified vectors."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Cross-site scripting"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://cweb.canon.jp/e-support/info/211221xss.html",
"refsource": "MISC",
"url": "https://cweb.canon.jp/e-support/info/211221xss.html"
},
{
"name": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/Service-Notice-Canon-Laser-Printer-and-Small-Office-Multifunctional-Printer-related-to-cross-site-scripting",
"refsource": "MISC",
"url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/Service-Notice-Canon-Laser-Printer-and-Small-Office-Multifunctional-Printer-related-to-cross-site-scripting"
},
{
"name": "https://www.canon-europe.com/support/product-security-latest-news/",
"refsource": "MISC",
"url": "https://www.canon-europe.com/support/product-security-latest-news/"
},
{
"name": "https://jvn.jp/en/jp/JVN64806328/index.html",
"refsource": "MISC",
"url": "https://jvn.jp/en/jp/JVN64806328/index.html"
},
{
"name": "https://jvn.jp/jp/JVN64806328/index.html",
"refsource": "MISC",
"url": "https://jvn.jp/jp/JVN64806328/index.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2021-20877",
"datePublished": "2022-02-08T10:30:31.000Z",
"dateReserved": "2020-12-17T00:00:00.000Z",
"dateUpdated": "2024-08-03T17:53:23.123Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2021-38154 (GCVE-0-2021-38154)
Vulnerability from cvelistv5 – Published: 2021-08-29 04:59 – Updated: 2024-08-04 01:37Summary
Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, allow remote attackers to modify an e-mail address setting, and thus cause the device to send sensitive information through e-mail to the attacker. For example, an incoming FAX may be sent through e-mail to the attacker. This occurs when a PIN is not required for General User Mode, as exploited in the wild in August 2021.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://www.usa.canon.com/internet/portal/us/home… | x_refsource_MISC |
| https://protocolpolice.nl/CVE-2021-38154_Protocol… | x_refsource_MISC |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-04T01:37:16.022Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://protocolpolice.nl/CVE-2021-38154_Protocol_Police_Catwalk_Alert"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, allow remote attackers to modify an e-mail address setting, and thus cause the device to send sensitive information through e-mail to the attacker. For example, an incoming FAX may be sent through e-mail to the attacker. This occurs when a PIN is not required for General User Mode, as exploited in the wild in August 2021."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2021-08-29T04:59:18.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"tags": [
"x_refsource_MISC"
],
"url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://protocolpolice.nl/CVE-2021-38154_Protocol_Police_Catwalk_Alert"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2021-38154",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, allow remote attackers to modify an e-mail address setting, and thus cause the device to send sensitive information through e-mail to the attacker. For example, an incoming FAX may be sent through e-mail to the attacker. This occurs when a PIN is not required for General User Mode, as exploited in the wild in August 2021."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories",
"refsource": "MISC",
"url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories"
},
{
"name": "https://protocolpolice.nl/CVE-2021-38154_Protocol_Police_Catwalk_Alert",
"refsource": "MISC",
"url": "https://protocolpolice.nl/CVE-2021-38154_Protocol_Police_Catwalk_Alert"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2021-38154",
"datePublished": "2021-08-29T04:59:18.000Z",
"dateReserved": "2021-08-06T00:00:00.000Z",
"dateUpdated": "2024-08-04T01:37:16.022Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}