Search

Find a vulnerability

Search criteria

    68 vulnerabilities by canon

    CVE-2026-9262 (GCVE-0-2026-9262)

    Vulnerability from nvd – Published: 2026-06-15 23:40 – Updated: 2026-06-16 15:01
    VLAI
    Summary
    Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-16 15:01 UTC
    CWE
    • CWE-1188 - Initialization of a resource with an insecure default
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-9262",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-16T15:01:20.368197Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-16T15:01:31.260Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EOS Network Setting Tool for Windows",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.5.0 or earlier"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EOS Network Setting Tool for macOS",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.5.0 or earlier"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "This issue was discovered by Ryan Hausknecht (@haus3c)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
                }
              ],
              "value": "Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "PASSIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1188",
                  "description": "CWE-1188 Initialization of a resource with an insecure default",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-15T23:40:15.216Z",
            "orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
            "shortName": "Canon"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://psirt.canon/advisory-information/cp2026-005/"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://canon.jp/support/support-info/260615vulnerability-response"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.usa.canon.com/about-us/to-our-customers/cpa2026-005-vulnerability-remediation-for-eos-network-setting-tool"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.canon-europe.com/support/product-security/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
        "assignerShortName": "Canon",
        "cveId": "CVE-2026-9262",
        "datePublished": "2026-06-15T23:40:15.216Z",
        "dateReserved": "2026-05-21T23:14:55.152Z",
        "dateUpdated": "2026-06-16T15:01:31.260Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-9261 (GCVE-0-2026-9261)

    Vulnerability from nvd – Published: 2026-06-15 23:39 – Updated: 2026-06-18 03:55
    VLAI
    Summary
    Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-17 00:00 UTC
    CWE
    • CWE-327 - Use of a Broken or Risky Cryptographic Algorithm
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-9261",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-17T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-18T03:55:38.801Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EOS Network Setting Tool for Windows",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.5.0 or earlier"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EOS Network Setting Tool for macOS",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.5.0 or earlier"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "This issue was discovered by Ryan Hausknecht (@haus3c)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
                }
              ],
              "value": "Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.6,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "PASSIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.8,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-327",
                  "description": "CWE-327: Use of a Broken or Risky Cryptographic Algorithm",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-15T23:39:23.700Z",
            "orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
            "shortName": "Canon"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://psirt.canon/advisory-information/cp2026-005/"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://canon.jp/support/support-info/260615vulnerability-response"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.usa.canon.com/about-us/to-our-customers/cpa2026-005-vulnerability-remediation-for-eos-network-setting-tool"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.canon-europe.com/support/product-security/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
        "assignerShortName": "Canon",
        "cveId": "CVE-2026-9261",
        "datePublished": "2026-06-15T23:39:23.700Z",
        "dateReserved": "2026-05-21T23:14:53.345Z",
        "dateUpdated": "2026-06-18T03:55:38.801Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-9260 (GCVE-0-2026-9260)

    Vulnerability from nvd – Published: 2026-06-15 23:38 – Updated: 2026-06-16 12:41
    VLAI
    Summary
    Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-16 12:41 UTC
    CWE
    • CWE-321 - Use of hard-coded cryptographic key
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-9260",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-16T12:41:33.426171Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-16T12:41:43.181Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EOS Network Setting Tool for Windows",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.5.0 or earlier"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EOS Network Setting Tool for macOS",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.5.0 or earlier"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "This issue was discovered by Ryan Hausknecht (@haus3c)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
                }
              ],
              "value": "Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 6.2,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-321",
                  "description": "CWE-321 Use of hard-coded cryptographic key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-15T23:38:29.951Z",
            "orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
            "shortName": "Canon"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://psirt.canon/advisory-information/cp2026-005/"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://canon.jp/support/support-info/260615vulnerability-response"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.usa.canon.com/about-us/to-our-customers/cpa2026-005-vulnerability-remediation-for-eos-network-setting-tool"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.canon-europe.com/support/product-security/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
        "assignerShortName": "Canon",
        "cveId": "CVE-2026-9260",
        "datePublished": "2026-06-15T23:38:29.951Z",
        "dateReserved": "2026-05-21T23:14:51.893Z",
        "dateUpdated": "2026-06-16T12:41:43.181Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-9259 (GCVE-0-2026-9259)

    Vulnerability from nvd – Published: 2026-06-15 23:36 – Updated: 2026-06-16 12:43
    VLAI
    Summary
    Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-16 12:43 UTC
    CWE
    • CWE-295 - Improper certificate validation
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-9259",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-16T12:43:13.289990Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-16T12:43:21.760Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EOS Network Setting Tool for Windows",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.5.0 or earlier"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EOS Network Setting Tool for macOS",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.5.0 or earlier"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "This issue was discovered by Ryan Hausknecht (@haus3c)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
                }
              ],
              "value": "Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "PASSIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-295",
                  "description": "CWE-295 Improper certificate validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-15T23:36:28.761Z",
            "orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
            "shortName": "Canon"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://psirt.canon/advisory-information/cp2026-005/"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://canon.jp/support/support-info/260615vulnerability-response"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.usa.canon.com/about-us/to-our-customers/cpa2026-005-vulnerability-remediation-for-eos-network-setting-tool"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.canon-europe.com/support/product-security/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
        "assignerShortName": "Canon",
        "cveId": "CVE-2026-9259",
        "datePublished": "2026-06-15T23:36:28.761Z",
        "dateReserved": "2026-05-21T23:14:50.204Z",
        "dateUpdated": "2026-06-16T12:43:21.760Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-9258 (GCVE-0-2026-9258)

    Vulnerability from nvd – Published: 2026-06-15 23:35 – Updated: 2026-06-16 12:47
    VLAI
    Summary
    Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-16 12:47 UTC
    CWE
    • CWE-295 - Improper certificate validation
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-9258",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-16T12:47:09.464807Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-16T12:47:23.858Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EOS Network Setting Tool for Windows",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.5.0 or earlier"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EOS Network Setting Tool for macOS",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.5.0 or earlier"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "This issue was discovered by Ryan Hausknecht (@haus3c)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
                }
              ],
              "value": "Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "PASSIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-295",
                  "description": "CWE-295 Improper certificate validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-15T23:35:41.442Z",
            "orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
            "shortName": "Canon"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://psirt.canon/advisory-information/cp2026-005/"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://canon.jp/support/support-info/260615vulnerability-response"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.usa.canon.com/about-us/to-our-customers/cpa2026-005-vulnerability-remediation-for-eos-network-setting-tool"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.canon-europe.com/support/product-security/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
        "assignerShortName": "Canon",
        "cveId": "CVE-2026-9258",
        "datePublished": "2026-06-15T23:35:41.442Z",
        "dateReserved": "2026-05-21T23:14:48.638Z",
        "dateUpdated": "2026-06-16T12:47:23.858Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-2184 (GCVE-0-2024-2184)

    Vulnerability from nvd – Published: 2024-03-11 00:26 – Updated: 2024-08-28 20:24
    VLAI
    Summary
    Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF740C Series/Satera MF640C Series/Satera LBP660C Series/Satera LBP620C Series firmware v12.07 and earlier, and Satera MF750C Series/Satera LBP670C Series firmware v03.09 and earlier sold in Japan.Color imageCLASS MF740C Series/Color imageCLASS MF640C Series/Color imageCLASS X MF1127C/Color imageCLASS LBP664Cdw/Color imageCLASS LBP622Cdw/Color imageCLASS X LBP1127C firmware v12.07 and earlier, and Color imageCLASS MF750C Series/Color imageCLASS X MF1333C/Color imageCLASS LBP674Cdw/Color imageCLASS X LBP1333C firmware v03.09 and earlier sold in US.i-SENSYS MF740C Series/i-SENSYS MF640C Series/C1127i Series/i-SENSYS LBP660C Series/i-SENSYS LBP620C Series/C1127P firmware v12.07 and earlier, and i-SENSYS MF750C Series/C1333i Series/i-SENSYS LBP673Cdw/C1333P firmware v03.09 and earlier sold in Europe.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-11 15:11 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    Canon Inc. Color imageCLASS MF740C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS MF640C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. i-SENSYS MF740C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. i-SENSYS MF640C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Satera MF740C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Satera MF640C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS X MF1127C Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. C1127i Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS LBP664Cdw Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS LBP622Cdw Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. i-SENSYS LBP660C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. i-SENSYS LBP620C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Satera LBP660C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Satera LBP620C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS X LBP1127C Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. C1127P Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS MF750C Series Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. i-SENSYS MF750C Series Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. Satera MF750C Series Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS X MF1333C Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. C1333i Series Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS LBP674Cdw Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. i-SENSYS LBP673Cdw Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. Satera LBP670C Series Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS X LBP1333C Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. C1333P Affected: v03.09 and earlier
    Create a notification for this product.
    canon color_imageclass_mf740c_series Affected: 0 , ≤ 12..07 (custom)
        cpe:2.3:h:canon:color_imageclass_mf740c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_mf640c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:color_imageclass_mf640c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon i-sensys_mf740c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:i-sensys_mf740c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon i-sensys_mf640c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:i-sensys_mf640c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon satera_mf740c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:satera_mf740c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_x_mf1127c Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:color_imageclass_x_mf1127c:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_lbp664cdw Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:color_imageclass_lbp664cdw:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon c1127i_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:c1127i_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_lbp622cdw Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:color_imageclass_lbp622cdw:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon i-sensys_lbp660c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:i-sensys_lbp660c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon i-sensys_lbp620c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:i-sensys_lbp620c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon i-sensys_mf750c_series Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:i-sensys_mf750c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_x_lbp1333c Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:color_imageclass_x_lbp1333c:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon i-sensys_lbp673cdw Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:i-sensys_lbp673cdw:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon satera_lbp670c_series Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:satera_lbp670c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon c1333p Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:c1333p:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon satera_mf640c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:satera_mf640c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon satera_lbp620c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:satera_lbp620c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon satera_lbp660c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:satera_lbp660c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_x_lbp1127c Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:color_imageclass_x_lbp1127c:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_mf750c_series Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:color_imageclass_mf750c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon c1127p Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:c1127p:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon satera_mf750c_series Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:satera_mf750c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_x_mf1333c Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:color_imageclass_x_mf1333c:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon c1333i_series Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:c1333i_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_lbp674cdw Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:color_imageclass_lbp674cdw:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T19:03:39.266Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://psirt.canon/advisory-information/cp2024-002/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_mf740c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_mf740c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12..07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_mf640c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_mf640c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:i-sensys_mf740c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "i-sensys_mf740c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:i-sensys_mf640c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "i-sensys_mf640c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:satera_mf740c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "satera_mf740c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_x_mf1127c:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_x_mf1127c",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_lbp664cdw:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_lbp664cdw",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:c1127i_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "c1127i_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_lbp622cdw:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_lbp622cdw",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:i-sensys_lbp660c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "i-sensys_lbp660c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:i-sensys_lbp620c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "i-sensys_lbp620c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:i-sensys_mf750c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "i-sensys_mf750c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_x_lbp1333c:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_x_lbp1333c",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:i-sensys_lbp673cdw:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "i-sensys_lbp673cdw",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:satera_lbp670c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "satera_lbp670c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:c1333p:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "c1333p",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:satera_mf640c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "satera_mf640c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:satera_lbp620c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "satera_lbp620c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:satera_lbp660c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "satera_lbp660c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_x_lbp1127c:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_x_lbp1127c",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_mf750c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_mf750c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:c1127p:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "c1127p",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:satera_mf750c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "satera_mf750c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_x_mf1333c:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_x_mf1333c",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:c1333i_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "c1333i_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_lbp674cdw:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_lbp674cdw",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-2184",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-11T15:11:33.695685Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-28T20:24:54.597Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Color imageCLASS MF740C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS MF640C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "i-SENSYS MF740C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "i-SENSYS MF640C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Satera MF740C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Satera MF640C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS X MF1127C",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "C1127i Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS LBP664Cdw",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS LBP622Cdw",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "i-SENSYS LBP660C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "i-SENSYS LBP620C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Satera LBP660C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Satera LBP620C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS X LBP1127C",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "C1127P",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS MF750C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "i-SENSYS MF750C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "Satera MF750C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS X MF1333C",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "C1333i Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS LBP674Cdw",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "i-SENSYS LBP673Cdw",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "Satera LBP670C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS X LBP1333C",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "C1333P",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eBuffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF740C Series/Satera MF640C Series/Satera LBP660C Series/Satera LBP620C Series firmware v12.07 and earlier, and Satera MF750C Series/Satera LBP670C Series firmware v03.09 and earlier sold in Japan.Color imageCLASS MF740C Series/Color imageCLASS MF640C Series/Color imageCLASS X MF1127C/Color imageCLASS LBP664Cdw/Color imageCLASS LBP622Cdw/Color imageCLASS X LBP1127C firmware v12.07 and earlier, and Color imageCLASS MF750C Series/Color imageCLASS X MF1333C/Color imageCLASS LBP674Cdw/Color imageCLASS X LBP1333C firmware v03.09 and earlier sold in US.i-SENSYS MF740C Series/i-SENSYS MF640C Series/C1127i Series/i-SENSYS LBP660C Series/i-SENSYS LBP620C Series/C1127P firmware v12.07 and earlier, and i-SENSYS MF750C Series/C1333i Series/i-SENSYS LBP673Cdw/C1333P firmware v03.09 and earlier sold in Europe.\u003c/p\u003e"
                }
              ],
              "value": "Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF740C Series/Satera MF640C Series/Satera LBP660C Series/Satera LBP620C Series firmware v12.07 and earlier, and Satera MF750C Series/Satera LBP670C Series firmware v03.09 and earlier sold in Japan.Color imageCLASS MF740C Series/Color imageCLASS MF640C Series/Color imageCLASS X MF1127C/Color imageCLASS LBP664Cdw/Color imageCLASS LBP622Cdw/Color imageCLASS X LBP1127C firmware v12.07 and earlier, and Color imageCLASS MF750C Series/Color imageCLASS X MF1333C/Color imageCLASS LBP674Cdw/Color imageCLASS X LBP1333C firmware v03.09 and earlier sold in US.i-SENSYS MF740C Series/i-SENSYS MF640C Series/C1127i Series/i-SENSYS LBP660C Series/i-SENSYS LBP620C Series/C1127P firmware v12.07 and earlier, and i-SENSYS MF750C Series/C1333i Series/i-SENSYS LBP673Cdw/C1333P firmware v03.09 and earlier sold in Europe.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787: Out-of-bounds Write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-11T00:26:02.346Z",
            "orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
            "shortName": "Canon"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://psirt.canon/advisory-information/cp2024-002/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
        "assignerShortName": "Canon",
        "cveId": "CVE-2024-2184",
        "datePublished": "2024-03-11T00:26:02.346Z",
        "dateReserved": "2024-03-05T00:44:00.599Z",
        "dateUpdated": "2024-08-28T20:24:54.597Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-1764 (GCVE-0-2023-1764)

    Vulnerability from nvd – Published: 2023-05-17 00:00 – Updated: 2025-01-22 19:47
    VLAI
    Summary
    Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the communication of the software.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-01-22 19:47 UTC
    CWE
    • CWE-326 - Inadequate Encryption Strength
    Impacted products
    Vendor Product Version
    Canon Inc. Canon IJ NW Tool Affected: Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T05:57:24.994Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://psirt.canon/advisory-information/cp2023-002/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://psirt.canon/hardening/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-1764",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-01-22T19:47:15.479601Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-01-22T19:47:20.955Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Canon IJ NW Tool",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8)"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the communication of the software."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-326",
                  "description": "CWE-326: Inadequate Encryption Strength",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-05-17T00:00:00.000Z",
            "orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
            "shortName": "Canon"
          },
          "references": [
            {
              "url": "https://psirt.canon/advisory-information/cp2023-002/"
            },
            {
              "url": "https://psirt.canon/hardening/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
        "assignerShortName": "Canon",
        "cveId": "CVE-2023-1764",
        "datePublished": "2023-05-17T00:00:00.000Z",
        "dateReserved": "2023-03-31T00:00:00.000Z",
        "dateUpdated": "2025-01-22T19:47:20.955Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-1763 (GCVE-0-2023-1763)

    Vulnerability from nvd – Published: 2023-05-17 00:00 – Updated: 2025-01-22 19:47
    VLAI
    Summary
    Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the software.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-01-22 19:47 UTC
    CWE
    • CWE-549 - Missing Password Field Masking
    Impacted products
    Vendor Product Version
    Canon Inc. Canon IJ NW Tool Affected: Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T05:57:25.055Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://psirt.canon/advisory-information/cp2023-002/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://psirt.canon/hardening/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-1763",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-01-22T19:47:47.922240Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-01-22T19:47:54.570Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Canon IJ NW Tool",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8)"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the software."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-549",
                  "description": "CWE-549: Missing Password Field Masking",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-05-17T00:00:00.000Z",
            "orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
            "shortName": "Canon"
          },
          "references": [
            {
              "url": "https://psirt.canon/advisory-information/cp2023-002/"
            },
            {
              "url": "https://psirt.canon/hardening/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
        "assignerShortName": "Canon",
        "cveId": "CVE-2023-1763",
        "datePublished": "2023-05-17T00:00:00.000Z",
        "dateReserved": "2023-03-31T00:00:00.000Z",
        "dateUpdated": "2025-01-22T19:47:54.570Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-38765 (GCVE-0-2022-38765)

    Vulnerability from nvd – Published: 2022-12-08 00:00 – Updated: 2025-04-23 15:48
    VLAI
    Summary
    Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is able to gain unauthorized access to imaging records by tampering with the vitrea-view/studies/search patientId parameter.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-23 15:47 UTC
    CWE
    • n/a
    • CWE-639 - Authorization Bypass Through User-Controlled Key
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T11:02:14.515Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 6.5,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-38765",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-23T15:47:46.103729Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-639",
                    "description": "CWE-639 Authorization Bypass Through User-Controlled Key",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-23T15:48:17.869Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is able to gain unauthorized access to imaging records by tampering with the vitrea-view/studies/search patientId parameter."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-12-08T00:00:00.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2022-38765",
        "datePublished": "2022-12-08T00:00:00.000Z",
        "dateReserved": "2022-08-25T00:00:00.000Z",
        "dateUpdated": "2025-04-23T15:48:17.869Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-37461 (GCVE-0-2022-37461)

    Vulnerability from nvd – Published: 2022-09-30 13:26 – Updated: 2025-05-20 19:21
    VLAI
    Summary
    Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the input after the error subdirectory to the /vitrea-view/error/ subdirectory, or the (2) groupID, (3) offset, or (4) limit parameter to an Administrative Panel (Group and Users) page. There is a risk of an attacker retrieving patient information.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-05-20 19:20 UTC
    CWE
    • n/a
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T10:29:21.038Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.vitalimages.com/vitrea-vision/vitrea-view/"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=30693"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 6.1,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "LOW",
                  "privilegesRequired": "NONE",
                  "scope": "CHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-37461",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-05-20T19:20:54.108652Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-79",
                    "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-05-20T19:21:22.569Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the input after the error subdirectory to the /vitrea-view/error/ subdirectory, or the (2) groupID, (3) offset, or (4) limit parameter to an Administrative Panel (Group and Users) page. There is a risk of an attacker retrieving patient information."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-09-30T23:03:53.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.vitalimages.com/vitrea-vision/vitrea-view/"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=30693"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2022-37461",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the input after the error subdirectory to the /vitrea-view/error/ subdirectory, or the (2) groupID, (3) offset, or (4) limit parameter to an Administrative Panel (Group and Users) page. There is a risk of an attacker retrieving patient information."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://www.vitalimages.com/vitrea-vision/vitrea-view/",
                  "refsource": "MISC",
                  "url": "https://www.vitalimages.com/vitrea-vision/vitrea-view/"
                },
                {
                  "name": "https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=30693",
                  "refsource": "MISC",
                  "url": "https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=30693"
                },
                {
                  "name": "https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/",
                  "refsource": "CONFIRM",
                  "url": "https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2022-37461",
        "datePublished": "2022-09-30T13:26:37.000Z",
        "dateReserved": "2022-08-07T00:00:00.000Z",
        "dateUpdated": "2025-05-20T19:21:22.569Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-26111 (GCVE-0-2022-26111)

    Vulnerability from nvd – Published: 2022-04-25 14:38 – Updated: 2024-08-03 04:56
    VLAI
    Summary
    The BeanShell components of IRISNext through 9.8.28 allow execution of arbitrary commands on the target server by creating a custom search (or editing an existing/predefined search) of the documents. The search components permit adding BeanShell expressions that result in Remote Code Execution in the context of the IRISNext application user, running on the web server.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T04:56:37.823Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://varsnext.iriscorporate.com/"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2022-26111.pdf"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The BeanShell components of IRISNext through 9.8.28 allow execution of arbitrary commands on the target server by creating a custom search (or editing an existing/predefined search) of the documents. The search components permit adding BeanShell expressions that result in Remote Code Execution in the context of the IRISNext application user, running on the web server."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-04-25T14:38:12.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://varsnext.iriscorporate.com/"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2022-26111.pdf"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2022-26111",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The BeanShell components of IRISNext through 9.8.28 allow execution of arbitrary commands on the target server by creating a custom search (or editing an existing/predefined search) of the documents. The search components permit adding BeanShell expressions that result in Remote Code Execution in the context of the IRISNext application user, running on the web server."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://varsnext.iriscorporate.com/",
                  "refsource": "MISC",
                  "url": "https://varsnext.iriscorporate.com/"
                },
                {
                  "name": "https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2022-26111.pdf",
                  "refsource": "MISC",
                  "url": "https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2022-26111.pdf"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2022-26111",
        "datePublished": "2022-04-25T14:38:12.000Z",
        "dateReserved": "2022-02-25T00:00:00.000Z",
        "dateUpdated": "2024-08-03T04:56:37.823Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-26320 (GCVE-0-2022-26320)

    Vulnerability from nvd – Published: 2022-03-14 17:28 – Updated: 2024-10-07 16:04
    VLAI
    Summary
    The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with Fermat's factorization method. This allows efficient calculation of private RSA keys from the public key of a TLS certificate.
    Severity
    No CVSS data available.
    CWE
    • n/a
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T05:03:32.548Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://global.canon/en/support/security/index.html"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://fermatattack.secvuln.info"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://www.fujifilm.com/fbglobal/eng/company/news/notice/2022/0302_rsakey_announce.html"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://safezoneswupdate.com"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with Fermat\u0027s factorization method. This allows efficient calculation of private RSA keys from the public key of a TLS certificate."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-07T16:04:03.893Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://global.canon/en/support/security/index.html"
            },
            {
              "url": "https://fermatattack.secvuln.info"
            },
            {
              "url": "https://www.fujifilm.com/fbglobal/eng/company/news/notice/2022/0302_rsakey_announce.html"
            },
            {
              "url": "https://www.rambus.com/security/response-center/advisories/rmbs-2021-01/"
            },
            {
              "url": "https://web.archive.org/web/20220922042721/https://safezoneswupdate.com/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2022-26320",
        "datePublished": "2022-03-14T17:28:04.000Z",
        "dateReserved": "2022-02-28T00:00:00.000Z",
        "dateUpdated": "2024-10-07T16:04:03.893Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-20877 (GCVE-0-2021-20877)

    Vulnerability from nvd – Published: 2022-02-08 10:30 – Updated: 2024-08-03 17:53
    VLAI
    Summary
    Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series (MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series (LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS (LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER (2206IF, 2204N, and 2204F) sold in Europe) allows remote attackers to inject an arbitrary script via unspecified vectors.
    Severity
    No CVSS data available.
    CWE
    • Cross-site scripting
    Impacted products
    Vendor Product Version
    Canon Canon laser printers and small office multifunctional printers Affected: LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series(MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series(LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS(LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER(2206IF, 2204N, and 2204F) sold in Europe
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T17:53:23.123Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://cweb.canon.jp/e-support/info/211221xss.html"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/Service-Notice-Canon-Laser-Printer-and-Small-Office-Multifunctional-Printer-related-to-cross-site-scripting"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.canon-europe.com/support/product-security-latest-news/"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/jp/JVN64806328/index.html"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jvn.jp/jp/JVN64806328/index.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Canon laser printers and small office multifunctional printers",
              "vendor": "Canon",
              "versions": [
                {
                  "status": "affected",
                  "version": "LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series(MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series(LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS(LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER(2206IF, 2204N, and 2204F) sold in Europe"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series (MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series (LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS (LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER (2206IF, 2204N, and 2204F) sold in Europe) allows remote attackers to inject an arbitrary script via unspecified vectors."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Cross-site scripting",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-02-08T10:30:31.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://cweb.canon.jp/e-support/info/211221xss.html"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/Service-Notice-Canon-Laser-Printer-and-Small-Office-Multifunctional-Printer-related-to-cross-site-scripting"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.canon-europe.com/support/product-security-latest-news/"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jvn.jp/en/jp/JVN64806328/index.html"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jvn.jp/jp/JVN64806328/index.html"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vultures@jpcert.or.jp",
              "ID": "CVE-2021-20877",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Canon laser printers and small office multifunctional printers",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series(MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series(LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS(LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER(2206IF, 2204N, and 2204F) sold in Europe"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Canon"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series (MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series (LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS (LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER (2206IF, 2204N, and 2204F) sold in Europe) allows remote attackers to inject an arbitrary script via unspecified vectors."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Cross-site scripting"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://cweb.canon.jp/e-support/info/211221xss.html",
                  "refsource": "MISC",
                  "url": "https://cweb.canon.jp/e-support/info/211221xss.html"
                },
                {
                  "name": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/Service-Notice-Canon-Laser-Printer-and-Small-Office-Multifunctional-Printer-related-to-cross-site-scripting",
                  "refsource": "MISC",
                  "url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/Service-Notice-Canon-Laser-Printer-and-Small-Office-Multifunctional-Printer-related-to-cross-site-scripting"
                },
                {
                  "name": "https://www.canon-europe.com/support/product-security-latest-news/",
                  "refsource": "MISC",
                  "url": "https://www.canon-europe.com/support/product-security-latest-news/"
                },
                {
                  "name": "https://jvn.jp/en/jp/JVN64806328/index.html",
                  "refsource": "MISC",
                  "url": "https://jvn.jp/en/jp/JVN64806328/index.html"
                },
                {
                  "name": "https://jvn.jp/jp/JVN64806328/index.html",
                  "refsource": "MISC",
                  "url": "https://jvn.jp/jp/JVN64806328/index.html"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2021-20877",
        "datePublished": "2022-02-08T10:30:31.000Z",
        "dateReserved": "2020-12-17T00:00:00.000Z",
        "dateUpdated": "2024-08-03T17:53:23.123Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-38154 (GCVE-0-2021-38154)

    Vulnerability from nvd – Published: 2021-08-29 04:59 – Updated: 2024-08-04 01:37
    VLAI Previdian
    Summary
    Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, allow remote attackers to modify an e-mail address setting, and thus cause the device to send sensitive information through e-mail to the attacker. For example, an incoming FAX may be sent through e-mail to the attacker. This occurs when a PIN is not required for General User Mode, as exploited in the wild in August 2021.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T01:37:16.022Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://protocolpolice.nl/CVE-2021-38154_Protocol_Police_Catwalk_Alert"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, allow remote attackers to modify an e-mail address setting, and thus cause the device to send sensitive information through e-mail to the attacker. For example, an incoming FAX may be sent through e-mail to the attacker. This occurs when a PIN is not required for General User Mode, as exploited in the wild in August 2021."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-08-29T04:59:18.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://protocolpolice.nl/CVE-2021-38154_Protocol_Police_Catwalk_Alert"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2021-38154",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, allow remote attackers to modify an e-mail address setting, and thus cause the device to send sensitive information through e-mail to the attacker. For example, an incoming FAX may be sent through e-mail to the attacker. This occurs when a PIN is not required for General User Mode, as exploited in the wild in August 2021."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories",
                  "refsource": "MISC",
                  "url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories"
                },
                {
                  "name": "https://protocolpolice.nl/CVE-2021-38154_Protocol_Police_Catwalk_Alert",
                  "refsource": "MISC",
                  "url": "https://protocolpolice.nl/CVE-2021-38154_Protocol_Police_Catwalk_Alert"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2021-38154",
        "datePublished": "2021-08-29T04:59:18.000Z",
        "dateReserved": "2021-08-06T00:00:00.000Z",
        "dateUpdated": "2024-08-04T01:37:16.022Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-39368 (GCVE-0-2021-39368)

    Vulnerability from nvd – Published: 2021-08-22 23:21 – Updated: 2024-08-04 02:06
    VLAI
    Summary
    Canon Oce Print Exec Workgroup 1.3.2 allows XSS via the lang parameter.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T02:06:42.488Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://github.com/IthacaLabs/Canon/tree/main/OCE_Print_Exec_Workgroup_Version_1_3_2/XSS_HTMLi"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Canon Oce Print Exec Workgroup 1.3.2 allows XSS via the lang parameter."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-08-22T23:21:13.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/IthacaLabs/Canon/tree/main/OCE_Print_Exec_Workgroup_Version_1_3_2/XSS_HTMLi"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2021-39368",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Canon Oce Print Exec Workgroup 1.3.2 allows XSS via the lang parameter."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://github.com/IthacaLabs/Canon/tree/main/OCE_Print_Exec_Workgroup_Version_1_3_2/XSS_HTMLi",
                  "refsource": "MISC",
                  "url": "https://github.com/IthacaLabs/Canon/tree/main/OCE_Print_Exec_Workgroup_Version_1_3_2/XSS_HTMLi"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2021-39368",
        "datePublished": "2021-08-22T23:21:13.000Z",
        "dateReserved": "2021-08-22T00:00:00.000Z",
        "dateUpdated": "2024-08-04T02:06:42.488Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-39367 (GCVE-0-2021-39367)

    Vulnerability from nvd – Published: 2021-08-22 23:21 – Updated: 2024-08-04 02:06
    VLAI
    Summary
    Canon Oce Print Exec Workgroup 1.3.2 allows Host header injection.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T02:06:42.493Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://github.com/IthacaLabs/Canon/tree/main/OCE_Print_Exec_Workgroup_Version_1_3_2/HHI"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Canon Oce Print Exec Workgroup 1.3.2 allows Host header injection."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-08-22T23:21:03.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/IthacaLabs/Canon/tree/main/OCE_Print_Exec_Workgroup_Version_1_3_2/HHI"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2021-39367",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Canon Oce Print Exec Workgroup 1.3.2 allows Host header injection."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://github.com/IthacaLabs/Canon/tree/main/OCE_Print_Exec_Workgroup_Version_1_3_2/HHI",
                  "refsource": "MISC",
                  "url": "https://github.com/IthacaLabs/Canon/tree/main/OCE_Print_Exec_Workgroup_Version_1_3_2/HHI"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2021-39367",
        "datePublished": "2021-08-22T23:21:03.000Z",
        "dateReserved": "2021-08-22T00:00:00.000Z",
        "dateUpdated": "2024-08-04T02:06:42.493Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2026-9262 (GCVE-0-2026-9262)

    Vulnerability from cvelistv5 – Published: 2026-06-15 23:40 – Updated: 2026-06-16 15:01
    VLAI
    Summary
    Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-16 15:01 UTC
    CWE
    • CWE-1188 - Initialization of a resource with an insecure default
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-9262",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-16T15:01:20.368197Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-16T15:01:31.260Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EOS Network Setting Tool for Windows",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.5.0 or earlier"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EOS Network Setting Tool for macOS",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.5.0 or earlier"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "This issue was discovered by Ryan Hausknecht (@haus3c)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
                }
              ],
              "value": "Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "PASSIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1188",
                  "description": "CWE-1188 Initialization of a resource with an insecure default",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-15T23:40:15.216Z",
            "orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
            "shortName": "Canon"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://psirt.canon/advisory-information/cp2026-005/"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://canon.jp/support/support-info/260615vulnerability-response"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.usa.canon.com/about-us/to-our-customers/cpa2026-005-vulnerability-remediation-for-eos-network-setting-tool"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.canon-europe.com/support/product-security/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
        "assignerShortName": "Canon",
        "cveId": "CVE-2026-9262",
        "datePublished": "2026-06-15T23:40:15.216Z",
        "dateReserved": "2026-05-21T23:14:55.152Z",
        "dateUpdated": "2026-06-16T15:01:31.260Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-9261 (GCVE-0-2026-9261)

    Vulnerability from cvelistv5 – Published: 2026-06-15 23:39 – Updated: 2026-06-18 03:55
    VLAI
    Summary
    Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-17 00:00 UTC
    CWE
    • CWE-327 - Use of a Broken or Risky Cryptographic Algorithm
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-9261",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-17T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-18T03:55:38.801Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EOS Network Setting Tool for Windows",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.5.0 or earlier"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EOS Network Setting Tool for macOS",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.5.0 or earlier"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "This issue was discovered by Ryan Hausknecht (@haus3c)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
                }
              ],
              "value": "Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.6,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "PASSIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.8,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-327",
                  "description": "CWE-327: Use of a Broken or Risky Cryptographic Algorithm",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-15T23:39:23.700Z",
            "orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
            "shortName": "Canon"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://psirt.canon/advisory-information/cp2026-005/"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://canon.jp/support/support-info/260615vulnerability-response"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.usa.canon.com/about-us/to-our-customers/cpa2026-005-vulnerability-remediation-for-eos-network-setting-tool"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.canon-europe.com/support/product-security/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
        "assignerShortName": "Canon",
        "cveId": "CVE-2026-9261",
        "datePublished": "2026-06-15T23:39:23.700Z",
        "dateReserved": "2026-05-21T23:14:53.345Z",
        "dateUpdated": "2026-06-18T03:55:38.801Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-9260 (GCVE-0-2026-9260)

    Vulnerability from cvelistv5 – Published: 2026-06-15 23:38 – Updated: 2026-06-16 12:41
    VLAI
    Summary
    Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-16 12:41 UTC
    CWE
    • CWE-321 - Use of hard-coded cryptographic key
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-9260",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-16T12:41:33.426171Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-16T12:41:43.181Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EOS Network Setting Tool for Windows",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.5.0 or earlier"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EOS Network Setting Tool for macOS",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.5.0 or earlier"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "This issue was discovered by Ryan Hausknecht (@haus3c)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
                }
              ],
              "value": "Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 6.2,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-321",
                  "description": "CWE-321 Use of hard-coded cryptographic key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-15T23:38:29.951Z",
            "orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
            "shortName": "Canon"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://psirt.canon/advisory-information/cp2026-005/"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://canon.jp/support/support-info/260615vulnerability-response"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.usa.canon.com/about-us/to-our-customers/cpa2026-005-vulnerability-remediation-for-eos-network-setting-tool"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.canon-europe.com/support/product-security/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
        "assignerShortName": "Canon",
        "cveId": "CVE-2026-9260",
        "datePublished": "2026-06-15T23:38:29.951Z",
        "dateReserved": "2026-05-21T23:14:51.893Z",
        "dateUpdated": "2026-06-16T12:41:43.181Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-9259 (GCVE-0-2026-9259)

    Vulnerability from cvelistv5 – Published: 2026-06-15 23:36 – Updated: 2026-06-16 12:43
    VLAI
    Summary
    Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-16 12:43 UTC
    CWE
    • CWE-295 - Improper certificate validation
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-9259",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-16T12:43:13.289990Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-16T12:43:21.760Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EOS Network Setting Tool for Windows",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.5.0 or earlier"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EOS Network Setting Tool for macOS",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.5.0 or earlier"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "This issue was discovered by Ryan Hausknecht (@haus3c)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
                }
              ],
              "value": "Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "PASSIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-295",
                  "description": "CWE-295 Improper certificate validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-15T23:36:28.761Z",
            "orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
            "shortName": "Canon"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://psirt.canon/advisory-information/cp2026-005/"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://canon.jp/support/support-info/260615vulnerability-response"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.usa.canon.com/about-us/to-our-customers/cpa2026-005-vulnerability-remediation-for-eos-network-setting-tool"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.canon-europe.com/support/product-security/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
        "assignerShortName": "Canon",
        "cveId": "CVE-2026-9259",
        "datePublished": "2026-06-15T23:36:28.761Z",
        "dateReserved": "2026-05-21T23:14:50.204Z",
        "dateUpdated": "2026-06-16T12:43:21.760Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-9258 (GCVE-0-2026-9258)

    Vulnerability from cvelistv5 – Published: 2026-06-15 23:35 – Updated: 2026-06-16 12:47
    VLAI
    Summary
    Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-16 12:47 UTC
    CWE
    • CWE-295 - Improper certificate validation
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-9258",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-16T12:47:09.464807Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-16T12:47:23.858Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EOS Network Setting Tool for Windows",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.5.0 or earlier"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EOS Network Setting Tool for macOS",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.5.0 or earlier"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "This issue was discovered by Ryan Hausknecht (@haus3c)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
                }
              ],
              "value": "Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier"
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "PASSIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-295",
                  "description": "CWE-295 Improper certificate validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-15T23:35:41.442Z",
            "orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
            "shortName": "Canon"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://psirt.canon/advisory-information/cp2026-005/"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://canon.jp/support/support-info/260615vulnerability-response"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.usa.canon.com/about-us/to-our-customers/cpa2026-005-vulnerability-remediation-for-eos-network-setting-tool"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.canon-europe.com/support/product-security/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
        "assignerShortName": "Canon",
        "cveId": "CVE-2026-9258",
        "datePublished": "2026-06-15T23:35:41.442Z",
        "dateReserved": "2026-05-21T23:14:48.638Z",
        "dateUpdated": "2026-06-16T12:47:23.858Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-2184 (GCVE-0-2024-2184)

    Vulnerability from cvelistv5 – Published: 2024-03-11 00:26 – Updated: 2024-08-28 20:24
    VLAI
    Summary
    Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF740C Series/Satera MF640C Series/Satera LBP660C Series/Satera LBP620C Series firmware v12.07 and earlier, and Satera MF750C Series/Satera LBP670C Series firmware v03.09 and earlier sold in Japan.Color imageCLASS MF740C Series/Color imageCLASS MF640C Series/Color imageCLASS X MF1127C/Color imageCLASS LBP664Cdw/Color imageCLASS LBP622Cdw/Color imageCLASS X LBP1127C firmware v12.07 and earlier, and Color imageCLASS MF750C Series/Color imageCLASS X MF1333C/Color imageCLASS LBP674Cdw/Color imageCLASS X LBP1333C firmware v03.09 and earlier sold in US.i-SENSYS MF740C Series/i-SENSYS MF640C Series/C1127i Series/i-SENSYS LBP660C Series/i-SENSYS LBP620C Series/C1127P firmware v12.07 and earlier, and i-SENSYS MF750C Series/C1333i Series/i-SENSYS LBP673Cdw/C1333P firmware v03.09 and earlier sold in Europe.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-11 15:11 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    Canon Inc. Color imageCLASS MF740C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS MF640C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. i-SENSYS MF740C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. i-SENSYS MF640C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Satera MF740C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Satera MF640C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS X MF1127C Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. C1127i Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS LBP664Cdw Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS LBP622Cdw Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. i-SENSYS LBP660C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. i-SENSYS LBP620C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Satera LBP660C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Satera LBP620C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS X LBP1127C Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. C1127P Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS MF750C Series Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. i-SENSYS MF750C Series Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. Satera MF750C Series Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS X MF1333C Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. C1333i Series Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS LBP674Cdw Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. i-SENSYS LBP673Cdw Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. Satera LBP670C Series Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS X LBP1333C Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. C1333P Affected: v03.09 and earlier
    Create a notification for this product.
    canon color_imageclass_mf740c_series Affected: 0 , ≤ 12..07 (custom)
        cpe:2.3:h:canon:color_imageclass_mf740c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_mf640c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:color_imageclass_mf640c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon i-sensys_mf740c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:i-sensys_mf740c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon i-sensys_mf640c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:i-sensys_mf640c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon satera_mf740c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:satera_mf740c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_x_mf1127c Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:color_imageclass_x_mf1127c:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_lbp664cdw Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:color_imageclass_lbp664cdw:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon c1127i_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:c1127i_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_lbp622cdw Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:color_imageclass_lbp622cdw:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon i-sensys_lbp660c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:i-sensys_lbp660c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon i-sensys_lbp620c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:i-sensys_lbp620c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon i-sensys_mf750c_series Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:i-sensys_mf750c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_x_lbp1333c Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:color_imageclass_x_lbp1333c:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon i-sensys_lbp673cdw Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:i-sensys_lbp673cdw:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon satera_lbp670c_series Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:satera_lbp670c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon c1333p Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:c1333p:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon satera_mf640c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:satera_mf640c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon satera_lbp620c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:satera_lbp620c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon satera_lbp660c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:satera_lbp660c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_x_lbp1127c Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:color_imageclass_x_lbp1127c:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_mf750c_series Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:color_imageclass_mf750c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon c1127p Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:c1127p:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon satera_mf750c_series Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:satera_mf750c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_x_mf1333c Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:color_imageclass_x_mf1333c:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon c1333i_series Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:c1333i_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_lbp674cdw Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:color_imageclass_lbp674cdw:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T19:03:39.266Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://psirt.canon/advisory-information/cp2024-002/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_mf740c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_mf740c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12..07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_mf640c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_mf640c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:i-sensys_mf740c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "i-sensys_mf740c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:i-sensys_mf640c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "i-sensys_mf640c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:satera_mf740c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "satera_mf740c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_x_mf1127c:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_x_mf1127c",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_lbp664cdw:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_lbp664cdw",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:c1127i_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "c1127i_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_lbp622cdw:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_lbp622cdw",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:i-sensys_lbp660c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "i-sensys_lbp660c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:i-sensys_lbp620c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "i-sensys_lbp620c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:i-sensys_mf750c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "i-sensys_mf750c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_x_lbp1333c:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_x_lbp1333c",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:i-sensys_lbp673cdw:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "i-sensys_lbp673cdw",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:satera_lbp670c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "satera_lbp670c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:c1333p:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "c1333p",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:satera_mf640c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "satera_mf640c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:satera_lbp620c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "satera_lbp620c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:satera_lbp660c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "satera_lbp660c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_x_lbp1127c:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_x_lbp1127c",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_mf750c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_mf750c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:c1127p:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "c1127p",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:satera_mf750c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "satera_mf750c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_x_mf1333c:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_x_mf1333c",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:c1333i_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "c1333i_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_lbp674cdw:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_lbp674cdw",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-2184",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-11T15:11:33.695685Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-28T20:24:54.597Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Color imageCLASS MF740C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS MF640C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "i-SENSYS MF740C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "i-SENSYS MF640C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Satera MF740C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Satera MF640C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS X MF1127C",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "C1127i Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS LBP664Cdw",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS LBP622Cdw",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "i-SENSYS LBP660C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "i-SENSYS LBP620C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Satera LBP660C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Satera LBP620C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS X LBP1127C",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "C1127P",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS MF750C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "i-SENSYS MF750C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "Satera MF750C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS X MF1333C",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "C1333i Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS LBP674Cdw",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "i-SENSYS LBP673Cdw",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "Satera LBP670C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS X LBP1333C",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "C1333P",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eBuffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF740C Series/Satera MF640C Series/Satera LBP660C Series/Satera LBP620C Series firmware v12.07 and earlier, and Satera MF750C Series/Satera LBP670C Series firmware v03.09 and earlier sold in Japan.Color imageCLASS MF740C Series/Color imageCLASS MF640C Series/Color imageCLASS X MF1127C/Color imageCLASS LBP664Cdw/Color imageCLASS LBP622Cdw/Color imageCLASS X LBP1127C firmware v12.07 and earlier, and Color imageCLASS MF750C Series/Color imageCLASS X MF1333C/Color imageCLASS LBP674Cdw/Color imageCLASS X LBP1333C firmware v03.09 and earlier sold in US.i-SENSYS MF740C Series/i-SENSYS MF640C Series/C1127i Series/i-SENSYS LBP660C Series/i-SENSYS LBP620C Series/C1127P firmware v12.07 and earlier, and i-SENSYS MF750C Series/C1333i Series/i-SENSYS LBP673Cdw/C1333P firmware v03.09 and earlier sold in Europe.\u003c/p\u003e"
                }
              ],
              "value": "Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF740C Series/Satera MF640C Series/Satera LBP660C Series/Satera LBP620C Series firmware v12.07 and earlier, and Satera MF750C Series/Satera LBP670C Series firmware v03.09 and earlier sold in Japan.Color imageCLASS MF740C Series/Color imageCLASS MF640C Series/Color imageCLASS X MF1127C/Color imageCLASS LBP664Cdw/Color imageCLASS LBP622Cdw/Color imageCLASS X LBP1127C firmware v12.07 and earlier, and Color imageCLASS MF750C Series/Color imageCLASS X MF1333C/Color imageCLASS LBP674Cdw/Color imageCLASS X LBP1333C firmware v03.09 and earlier sold in US.i-SENSYS MF740C Series/i-SENSYS MF640C Series/C1127i Series/i-SENSYS LBP660C Series/i-SENSYS LBP620C Series/C1127P firmware v12.07 and earlier, and i-SENSYS MF750C Series/C1333i Series/i-SENSYS LBP673Cdw/C1333P firmware v03.09 and earlier sold in Europe.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787: Out-of-bounds Write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-11T00:26:02.346Z",
            "orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
            "shortName": "Canon"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://psirt.canon/advisory-information/cp2024-002/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
        "assignerShortName": "Canon",
        "cveId": "CVE-2024-2184",
        "datePublished": "2024-03-11T00:26:02.346Z",
        "dateReserved": "2024-03-05T00:44:00.599Z",
        "dateUpdated": "2024-08-28T20:24:54.597Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-1764 (GCVE-0-2023-1764)

    Vulnerability from cvelistv5 – Published: 2023-05-17 00:00 – Updated: 2025-01-22 19:47
    VLAI
    Summary
    Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the communication of the software.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-01-22 19:47 UTC
    CWE
    • CWE-326 - Inadequate Encryption Strength
    Impacted products
    Vendor Product Version
    Canon Inc. Canon IJ NW Tool Affected: Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T05:57:24.994Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://psirt.canon/advisory-information/cp2023-002/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://psirt.canon/hardening/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-1764",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-01-22T19:47:15.479601Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-01-22T19:47:20.955Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Canon IJ NW Tool",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8)"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the communication of the software."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-326",
                  "description": "CWE-326: Inadequate Encryption Strength",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-05-17T00:00:00.000Z",
            "orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
            "shortName": "Canon"
          },
          "references": [
            {
              "url": "https://psirt.canon/advisory-information/cp2023-002/"
            },
            {
              "url": "https://psirt.canon/hardening/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
        "assignerShortName": "Canon",
        "cveId": "CVE-2023-1764",
        "datePublished": "2023-05-17T00:00:00.000Z",
        "dateReserved": "2023-03-31T00:00:00.000Z",
        "dateUpdated": "2025-01-22T19:47:20.955Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-1763 (GCVE-0-2023-1763)

    Vulnerability from cvelistv5 – Published: 2023-05-17 00:00 – Updated: 2025-01-22 19:47
    VLAI
    Summary
    Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the software.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-01-22 19:47 UTC
    CWE
    • CWE-549 - Missing Password Field Masking
    Impacted products
    Vendor Product Version
    Canon Inc. Canon IJ NW Tool Affected: Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T05:57:25.055Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://psirt.canon/advisory-information/cp2023-002/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://psirt.canon/hardening/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-1763",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-01-22T19:47:47.922240Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-01-22T19:47:54.570Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Canon IJ NW Tool",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8)"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the software."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-549",
                  "description": "CWE-549: Missing Password Field Masking",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-05-17T00:00:00.000Z",
            "orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
            "shortName": "Canon"
          },
          "references": [
            {
              "url": "https://psirt.canon/advisory-information/cp2023-002/"
            },
            {
              "url": "https://psirt.canon/hardening/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
        "assignerShortName": "Canon",
        "cveId": "CVE-2023-1763",
        "datePublished": "2023-05-17T00:00:00.000Z",
        "dateReserved": "2023-03-31T00:00:00.000Z",
        "dateUpdated": "2025-01-22T19:47:54.570Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-38765 (GCVE-0-2022-38765)

    Vulnerability from cvelistv5 – Published: 2022-12-08 00:00 – Updated: 2025-04-23 15:48
    VLAI
    Summary
    Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is able to gain unauthorized access to imaging records by tampering with the vitrea-view/studies/search patientId parameter.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-23 15:47 UTC
    CWE
    • n/a
    • CWE-639 - Authorization Bypass Through User-Controlled Key
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T11:02:14.515Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 6.5,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-38765",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-23T15:47:46.103729Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-639",
                    "description": "CWE-639 Authorization Bypass Through User-Controlled Key",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-23T15:48:17.869Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is able to gain unauthorized access to imaging records by tampering with the vitrea-view/studies/search patientId parameter."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-12-08T00:00:00.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2022-38765",
        "datePublished": "2022-12-08T00:00:00.000Z",
        "dateReserved": "2022-08-25T00:00:00.000Z",
        "dateUpdated": "2025-04-23T15:48:17.869Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-37461 (GCVE-0-2022-37461)

    Vulnerability from cvelistv5 – Published: 2022-09-30 13:26 – Updated: 2025-05-20 19:21
    VLAI
    Summary
    Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the input after the error subdirectory to the /vitrea-view/error/ subdirectory, or the (2) groupID, (3) offset, or (4) limit parameter to an Administrative Panel (Group and Users) page. There is a risk of an attacker retrieving patient information.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-05-20 19:20 UTC
    CWE
    • n/a
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T10:29:21.038Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.vitalimages.com/vitrea-vision/vitrea-view/"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=30693"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 6.1,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "LOW",
                  "privilegesRequired": "NONE",
                  "scope": "CHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-37461",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-05-20T19:20:54.108652Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-79",
                    "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-05-20T19:21:22.569Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the input after the error subdirectory to the /vitrea-view/error/ subdirectory, or the (2) groupID, (3) offset, or (4) limit parameter to an Administrative Panel (Group and Users) page. There is a risk of an attacker retrieving patient information."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-09-30T23:03:53.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.vitalimages.com/vitrea-vision/vitrea-view/"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=30693"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2022-37461",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the input after the error subdirectory to the /vitrea-view/error/ subdirectory, or the (2) groupID, (3) offset, or (4) limit parameter to an Administrative Panel (Group and Users) page. There is a risk of an attacker retrieving patient information."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://www.vitalimages.com/vitrea-vision/vitrea-view/",
                  "refsource": "MISC",
                  "url": "https://www.vitalimages.com/vitrea-vision/vitrea-view/"
                },
                {
                  "name": "https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=30693",
                  "refsource": "MISC",
                  "url": "https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=30693"
                },
                {
                  "name": "https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/",
                  "refsource": "CONFIRM",
                  "url": "https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2022-37461",
        "datePublished": "2022-09-30T13:26:37.000Z",
        "dateReserved": "2022-08-07T00:00:00.000Z",
        "dateUpdated": "2025-05-20T19:21:22.569Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-26111 (GCVE-0-2022-26111)

    Vulnerability from cvelistv5 – Published: 2022-04-25 14:38 – Updated: 2024-08-03 04:56
    VLAI
    Summary
    The BeanShell components of IRISNext through 9.8.28 allow execution of arbitrary commands on the target server by creating a custom search (or editing an existing/predefined search) of the documents. The search components permit adding BeanShell expressions that result in Remote Code Execution in the context of the IRISNext application user, running on the web server.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T04:56:37.823Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://varsnext.iriscorporate.com/"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2022-26111.pdf"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The BeanShell components of IRISNext through 9.8.28 allow execution of arbitrary commands on the target server by creating a custom search (or editing an existing/predefined search) of the documents. The search components permit adding BeanShell expressions that result in Remote Code Execution in the context of the IRISNext application user, running on the web server."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-04-25T14:38:12.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://varsnext.iriscorporate.com/"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2022-26111.pdf"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2022-26111",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The BeanShell components of IRISNext through 9.8.28 allow execution of arbitrary commands on the target server by creating a custom search (or editing an existing/predefined search) of the documents. The search components permit adding BeanShell expressions that result in Remote Code Execution in the context of the IRISNext application user, running on the web server."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://varsnext.iriscorporate.com/",
                  "refsource": "MISC",
                  "url": "https://varsnext.iriscorporate.com/"
                },
                {
                  "name": "https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2022-26111.pdf",
                  "refsource": "MISC",
                  "url": "https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2022-26111.pdf"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2022-26111",
        "datePublished": "2022-04-25T14:38:12.000Z",
        "dateReserved": "2022-02-25T00:00:00.000Z",
        "dateUpdated": "2024-08-03T04:56:37.823Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-26320 (GCVE-0-2022-26320)

    Vulnerability from cvelistv5 – Published: 2022-03-14 17:28 – Updated: 2024-10-07 16:04
    VLAI
    Summary
    The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with Fermat's factorization method. This allows efficient calculation of private RSA keys from the public key of a TLS certificate.
    Severity
    No CVSS data available.
    CWE
    • n/a
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T05:03:32.548Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://global.canon/en/support/security/index.html"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://fermatattack.secvuln.info"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://www.fujifilm.com/fbglobal/eng/company/news/notice/2022/0302_rsakey_announce.html"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://safezoneswupdate.com"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with Fermat\u0027s factorization method. This allows efficient calculation of private RSA keys from the public key of a TLS certificate."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-07T16:04:03.893Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://global.canon/en/support/security/index.html"
            },
            {
              "url": "https://fermatattack.secvuln.info"
            },
            {
              "url": "https://www.fujifilm.com/fbglobal/eng/company/news/notice/2022/0302_rsakey_announce.html"
            },
            {
              "url": "https://www.rambus.com/security/response-center/advisories/rmbs-2021-01/"
            },
            {
              "url": "https://web.archive.org/web/20220922042721/https://safezoneswupdate.com/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2022-26320",
        "datePublished": "2022-03-14T17:28:04.000Z",
        "dateReserved": "2022-02-28T00:00:00.000Z",
        "dateUpdated": "2024-10-07T16:04:03.893Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-20877 (GCVE-0-2021-20877)

    Vulnerability from cvelistv5 – Published: 2022-02-08 10:30 – Updated: 2024-08-03 17:53
    VLAI
    Summary
    Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series (MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series (LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS (LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER (2206IF, 2204N, and 2204F) sold in Europe) allows remote attackers to inject an arbitrary script via unspecified vectors.
    Severity
    No CVSS data available.
    CWE
    • Cross-site scripting
    Impacted products
    Vendor Product Version
    Canon Canon laser printers and small office multifunctional printers Affected: LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series(MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series(LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS(LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER(2206IF, 2204N, and 2204F) sold in Europe
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T17:53:23.123Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://cweb.canon.jp/e-support/info/211221xss.html"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/Service-Notice-Canon-Laser-Printer-and-Small-Office-Multifunctional-Printer-related-to-cross-site-scripting"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.canon-europe.com/support/product-security-latest-news/"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/jp/JVN64806328/index.html"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jvn.jp/jp/JVN64806328/index.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Canon laser printers and small office multifunctional printers",
              "vendor": "Canon",
              "versions": [
                {
                  "status": "affected",
                  "version": "LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series(MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series(LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS(LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER(2206IF, 2204N, and 2204F) sold in Europe"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series (MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series (LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS (LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER (2206IF, 2204N, and 2204F) sold in Europe) allows remote attackers to inject an arbitrary script via unspecified vectors."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Cross-site scripting",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-02-08T10:30:31.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://cweb.canon.jp/e-support/info/211221xss.html"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/Service-Notice-Canon-Laser-Printer-and-Small-Office-Multifunctional-Printer-related-to-cross-site-scripting"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.canon-europe.com/support/product-security-latest-news/"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jvn.jp/en/jp/JVN64806328/index.html"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jvn.jp/jp/JVN64806328/index.html"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vultures@jpcert.or.jp",
              "ID": "CVE-2021-20877",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Canon laser printers and small office multifunctional printers",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series(MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series(LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS(LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER(2206IF, 2204N, and 2204F) sold in Europe"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Canon"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series (MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series (LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS (LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER (2206IF, 2204N, and 2204F) sold in Europe) allows remote attackers to inject an arbitrary script via unspecified vectors."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Cross-site scripting"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://cweb.canon.jp/e-support/info/211221xss.html",
                  "refsource": "MISC",
                  "url": "https://cweb.canon.jp/e-support/info/211221xss.html"
                },
                {
                  "name": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/Service-Notice-Canon-Laser-Printer-and-Small-Office-Multifunctional-Printer-related-to-cross-site-scripting",
                  "refsource": "MISC",
                  "url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/Service-Notice-Canon-Laser-Printer-and-Small-Office-Multifunctional-Printer-related-to-cross-site-scripting"
                },
                {
                  "name": "https://www.canon-europe.com/support/product-security-latest-news/",
                  "refsource": "MISC",
                  "url": "https://www.canon-europe.com/support/product-security-latest-news/"
                },
                {
                  "name": "https://jvn.jp/en/jp/JVN64806328/index.html",
                  "refsource": "MISC",
                  "url": "https://jvn.jp/en/jp/JVN64806328/index.html"
                },
                {
                  "name": "https://jvn.jp/jp/JVN64806328/index.html",
                  "refsource": "MISC",
                  "url": "https://jvn.jp/jp/JVN64806328/index.html"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2021-20877",
        "datePublished": "2022-02-08T10:30:31.000Z",
        "dateReserved": "2020-12-17T00:00:00.000Z",
        "dateUpdated": "2024-08-03T17:53:23.123Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-38154 (GCVE-0-2021-38154)

    Vulnerability from cvelistv5 – Published: 2021-08-29 04:59 – Updated: 2024-08-04 01:37
    VLAI Previdian
    Summary
    Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, allow remote attackers to modify an e-mail address setting, and thus cause the device to send sensitive information through e-mail to the attacker. For example, an incoming FAX may be sent through e-mail to the attacker. This occurs when a PIN is not required for General User Mode, as exploited in the wild in August 2021.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T01:37:16.022Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://protocolpolice.nl/CVE-2021-38154_Protocol_Police_Catwalk_Alert"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, allow remote attackers to modify an e-mail address setting, and thus cause the device to send sensitive information through e-mail to the attacker. For example, an incoming FAX may be sent through e-mail to the attacker. This occurs when a PIN is not required for General User Mode, as exploited in the wild in August 2021."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-08-29T04:59:18.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://protocolpolice.nl/CVE-2021-38154_Protocol_Police_Catwalk_Alert"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2021-38154",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, allow remote attackers to modify an e-mail address setting, and thus cause the device to send sensitive information through e-mail to the attacker. For example, an incoming FAX may be sent through e-mail to the attacker. This occurs when a PIN is not required for General User Mode, as exploited in the wild in August 2021."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories",
                  "refsource": "MISC",
                  "url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories"
                },
                {
                  "name": "https://protocolpolice.nl/CVE-2021-38154_Protocol_Police_Catwalk_Alert",
                  "refsource": "MISC",
                  "url": "https://protocolpolice.nl/CVE-2021-38154_Protocol_Police_Catwalk_Alert"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2021-38154",
        "datePublished": "2021-08-29T04:59:18.000Z",
        "dateReserved": "2021-08-06T00:00:00.000Z",
        "dateUpdated": "2024-08-04T01:37:16.022Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }