First published: Mon Jun 04 2018(Updated: )
** DISPUTED ** An issue was discovered on Canon LBP6650, LBP3370, LBP3460, and LBP7750C devices. It is possible to bypass the Administrator Mode authentication for /tlogin.cgi via vectors involving frame.cgi?page=DevStatus. NOTE: the vendor reportedly responded that this issue occurs when a customer keeps the default settings without using the countermeasures and best practices shown in the documentation.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Canon Lbp3370 Firmware | ||
Canon Lbp3370 | ||
Canon Lbp3460 Firmware | ||
Canon Lbp3460 | ||
Canon Lbp7750c Firmware | ||
Canon Lbp7750c | ||
Canon Lbp6650 Firmware | ||
Canon LBP6650 | ||
All of | ||
Canon Lbp3370 Firmware | ||
Canon Lbp3370 | ||
All of | ||
Canon Lbp3460 Firmware | ||
Canon Lbp3460 | ||
All of | ||
Canon Lbp7750c Firmware | ||
Canon Lbp7750c | ||
All of | ||
Canon Lbp6650 Firmware | ||
Canon LBP6650 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11692 is a vulnerability discovered on Canon LBP6650, LBP3370, LBP3460, and LBP7750C devices that allows bypassing of the Administrator Mode authentication.
CVE-2018-11692 has a severity rating of 9.8 (Critical).
Canon LBP3370 Firmware, Canon LBP3460 Firmware, and Canon LBP7750c Firmware are affected by CVE-2018-11692.
Exploiting CVE-2018-11692 involves using vectors involving frame.cgi?page=DevStatus to bypass the Administrator Mode authentication for /tlogin.cgi.
No, Canon LBP3370, LBP3460, and LBP7750c are not vulnerable to CVE-2018-11692.