First published: Mon Nov 16 2020(Updated: )
The WebTools component on Canon Oce ColorWave 3500 5.1.1.0 devices allows attackers to retrieve stored SMB credentials via the export feature, even though these are intentionally inaccessible in the UI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Canon Oce Colorwave 3500 Firmware | =5.1.1.0 | |
Canon Oce ColorWave 3500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-26508.
CVE-2020-26508 has a severity rating of critical.
Canon Oce ColorWave 3500 5.1.1.0 devices are affected by CVE-2020-26508.
CVE-2020-26508 allows attackers to retrieve stored SMB credentials via the export feature.
Currently, there is no available fix for CVE-2020-26508. It is recommended to follow the provided reference for updates and mitigation steps.