CVE-2020-26508: Critical severity canon oce colorwave 3500 vulnerability
Published Nov 16, 2020
·Updated
The WebTools component on Canon Oce ColorWave 3500 5.1.1.0 devices allows attackers to retrieve stored SMB credentials via the export feature, even though these are intentionally inaccessible in the UI.
Affected Software
2 affected components
Canon Oce Colorwave 3500 Firmware=5.1.1.0
Canon Oce ColorWave 3500
Event History
Nov 16, 2020
CVE Published
via MITRE·06:49 PM
Data Sourced
via MITRE·06:49 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-26508.
2
What is the severity of CVE-2020-26508?
CVE-2020-26508 has a severity rating of critical.
3
Which devices are affected by CVE-2020-26508?
Canon Oce ColorWave 3500 5.1.1.0 devices are affected by CVE-2020-26508.
4
What is the impact of CVE-2020-26508?
CVE-2020-26508 allows attackers to retrieve stored SMB credentials via the export feature.
5
Is there a fix available for CVE-2020-26508?
Currently, there is no available fix for CVE-2020-26508. It is recommended to follow the provided reference for updates and mitigation steps.