CSRF Vulnerability in Canon Oce Colorwave 500 Printer
CVE-2020-10671

8.8HIGH

Key Information:

Vendor

Canon

Vendor
CVE Published:
19 March 2020

What is CVE-2020-10671?

The Canon Oce Colorwave 500 printer features a web application that lacks essential CSRF protections, exposing it to potential misuse. This flaw allows an attacker to conduct unauthorized administrative actions by targeting an active session of a logged-in admin user. The vulnerability represents a system-wide issue, posing significant risks to the integrity and security of the device, particularly if not updated to the latest version where this issue has been addressed.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.