First published: Thu Mar 19 2020(Updated: )
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to authentication bypass on the page /home.jsp. An unauthenticated attacker able to connect to the device's web interface can get a copy of the documents uploaded by any users. NOTE: this is fixed in the latest version.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Canon Oce Colorwave 500 Firmware | =4.0.0.0 | |
Canon Oce Colorwave 500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-10669.
The severity of CVE-2020-10669 is high with a CVSS score of 7.5.
The affected software of CVE-2020-10669 is Canon Oce Colorwave 500 Firmware version 4.0.0.0.
Yes, Canon Oce Colorwave 500 Firmware version 4.0.0.0 is vulnerable to CVE-2020-10669.
An unauthenticated attacker can exploit CVE-2020-10669 by bypassing authentication on the /home.jsp page of the Canon Oce Colorwave 500 web application.