First published: Thu Mar 19 2020(Updated: )
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Reflected XSS in /home.jsp. The vulnerable parameter is openSI. NOTE: this is fixed in the latest version.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Canon Oce Colorwave 500 Firmware | <=4.0.0.0 | |
Canon Oce Colorwave 500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10668 is a vulnerability in the Canon Oce Colorwave 500 printer firmware version 4.0.0.0 that allows for Reflected XSS attacks.
The severity of CVE-2020-10668 is medium with a CVSS score of 6.1.
To exploit CVE-2020-10668, an attacker can craft a malicious link or script and trick a user into clicking on it, causing the script to execute on the user's browser.
To fix CVE-2020-10668, it is recommended to update the Canon Oce Colorwave 500 printer firmware to the latest version available, as the vulnerability has been fixed.
You can find more information about CVE-2020-10668 on the following sources: [link 1](http://packetstormsecurity.com/files/156833/Oce-Colorwave-500-CSRF-XSS-Authentication-Bypass.html), [link 2](http://seclists.org/fulldisclosure/2020/Mar/24), [link 3](https://www.redtimmy.com/red-teaming/hacking-the-oce-colorwave-printer-when-a-quick-security-assessment-determines-the-success-of-a-red-team-exercise/).