CVE-2021-38154: High severity Canon - vulnerability
Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, allow remote attackers to modify an e-mail address setting, and thus cause the device to send sensitive information through e-mail to the attacker. For example, an incoming FAX may be sent through e-mail to the attacker. This occurs when a PIN is not required for General User Mode, as exploited in the wild in August 2021.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable/turn off Catwalk Server HTTP access on the device to prevent remote attackers from modifying the e-mail address setting and causing the device to send sensitive information via e-mail.
Canon device web/HTTP interface (Catwalk Server) Catwalk Server for HTTP access = Disable if not required - Configuration
Configure the device so that General User Mode requires a PIN; the issue occurs when a PIN is not required for General User Mode.
Canon device user mode (General User Mode) PIN required for General User Mode = Enable PIN requirement
Event History
Frequently Asked Questions
What is CVE-2021-38154?
CVE-2021-38154 is a vulnerability found in certain Canon devices manufactured between 2012 and 2020.
How does CVE-2021-38154 work?
CVE-2021-38154 allows remote attackers to modify an e-mail address setting on the affected Canon devices, which can result in the device sending sensitive information to the attacker via e-mail.
What is the severity of CVE-2021-38154?
CVE-2021-38154 has a severity rating of 7.5, which is considered high.
Which Canon devices are affected by CVE-2021-38154?
Certain Canon devices manufactured between 2012 and 2020, such as imageRUNNER ADVANCE iR-ADV C5250, are affected by CVE-2021-38154.
How can CVE-2021-38154 be fixed?
To fix CVE-2021-38154, it is recommended to apply the necessary security patches or updates provided by Canon.