First published: Mon Sep 11 2006(Updated: )
The Remote UI in Canon imageRUNNER includes usernames and passwords when exporting an address book, which allows context-dependent attackers to obtain sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Canon Imagerunner C6800 | ||
Canon Imagerunner 8500 | ||
Canon Imagerunner 9070 | ||
Canon Imagerunner 6870 | ||
Canon Imagerunner 5020 | ||
Canon Imagerunner 2620 | ||
Canon Imagerunner C3220 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4680 is considered to be of medium severity due to the risk of exposing sensitive information.
To mitigate CVE-2006-4680, users should restrict access to the Remote UI and ensure sensitive information is not exported.
CVE-2006-4680 affects several Canon imageRUNNER devices, including models C6800, 8500, 9070, 6870, 5020, 2620, and C3220.
CVE-2006-4680 can expose usernames and passwords when an address book is exported.
Yes, CVE-2006-4680 can be exploited by context-dependent attackers with access to the Remote UI.