First published: Thu Mar 19 2020(Updated: )
The Canon Oce Colorwave 500 4.0.0.0 printer's web application is missing any form of CSRF protections. This is a system-wide issue. An attacker could perform administrative actions by targeting a logged-in administrative user. NOTE: this is fixed in the latest version.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Canon Oce Colorwave 500 Firmware | <=4.0.0.0 | |
Canon Oce Colorwave 500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-10671 is high with a severity value of 8.8.
CVE-2020-10671 affects the Canon Oce Colorwave 500 printer's web application by missing any form of CSRF protection.
The impact of CVE-2020-10671 is that an attacker could perform administrative actions by targeting a logged-in administrative user.
Yes, CVE-2020-10671 is fixed in the latest version of the Canon Oce Colorwave 500 firmware.
Yes, there are references related to CVE-2020-10671. You can find more information at the following links: [link1](http://packetstormsecurity.com/files/156833/Oce-Colorwave-500-CSRF-XSS-Authentication-Bypass.html), [link2](https://www.redtimmy.com/red-teaming/hacking-the-oce-colorwave-printer-when-a-quick-security-assessment-determines-the-success-of-a-red-team-exercise/)