First published: Fri Jun 21 2013(Updated: )
The default configuration of the administrative interface on the Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers does not require authentication, which allows remote attackers to modify the configuration by visiting the Advanced page. NOTE: the vendor has apparently responded by stating "for user convenience, the default setting does not require a password. However, if a user has a particular concern about third parties accessing the user's home printer, the default setting can be changed to add a password."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Canon MG3100 Printer | ||
Canon MG5300 Printer | ||
Canon MG6100 Series Printer | ||
Canon MP340 Printer | ||
Canon MP495 Printer | ||
Canon MX870 Printer | ||
Canon MX890 Printer | ||
Canon MX920 Printer | ||
Canon MX922 Printer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4613 has a high severity rating due to the lack of authentication on the administrative interface of several Canon printers.
To fix CVE-2013-4613, you should enable authentication on the printer's administrative interface through the settings.
CVE-2013-4613 affects the Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers.
An attacker could exploit CVE-2013-4613 to modify printer settings remotely without authentication.
A firmware update that includes a patch for CVE-2013-4613 may be available from Canon, so it's important to check for updates.