First published: Thu Mar 19 2020(Updated: )
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Reflected XSS in the parameter settingId of the settingDialogContent.jsp page. NOTE: this is fixed in the latest version.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Canon Oce Colorwave 500 Firmware | <=4.0.0.0 | |
Canon Oce Colorwave 500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-10670 is medium with a CVSS score of 6.1.
The Canon Oce Colorwave 500 4.0.0.0 printer becomes vulnerable to CVE-2020-10670 because of a reflected cross-site scripting (XSS) vulnerability in the parameter settingId of the settingDialogContent.jsp page.
The affected software for CVE-2020-10670 is Canon Oce Colorwave 500 firmware version 4.0.0.0.
No, the Canon Oce Colorwave 500 printer is not vulnerable to CVE-2020-10670, only the firmware version 4.0.0.0 is affected.
To fix the vulnerability in the Canon Oce Colorwave 500 4.0.0.0 printer, update to the latest version of the firmware.