CVE-2018-11692: Critical severity canon lbp3370 vulnerability
DISPUTED An issue was discovered on Canon LBP6650, LBP3370, LBP3460, and LBP7750C devices. It is possible to bypass the Administrator Mode authentication for /tlogin.cgi via vectors involving frame.cgi?page=DevStatus. NOTE: the vendor reportedly responded that this issue occurs when a customer keeps the default settings without using the countermeasures and best practices shown in the documentation.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11692?
CVE-2018-11692 is a vulnerability discovered on Canon LBP6650, LBP3370, LBP3460, and LBP7750C devices that allows bypassing of the Administrator Mode authentication.
How severe is CVE-2018-11692?
CVE-2018-11692 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2018-11692?
Canon LBP3370 Firmware, Canon LBP3460 Firmware, and Canon LBP7750c Firmware are affected by CVE-2018-11692.
How can I exploit CVE-2018-11692?
Exploiting CVE-2018-11692 involves using vectors involving frame.cgi?page=DevStatus to bypass the Administrator Mode authentication for /tlogin.cgi.
Are Canon LBP3370, LBP3460, and LBP7750c vulnerable to CVE-2018-11692?
No, Canon LBP3370, LBP3460, and LBP7750c are not vulnerable to CVE-2018-11692.