CVE-2013-4614

English/pages_MacUS/wls_set_content.html on the Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers shows the Wi-Fi PSK passphrase in cleartext, which allows physically proximate attackers to obtain sensitive information by reading the screen of an unattended workstation.
Configurations

Configuration 1 (hide)

OR cpe:2.3:h:canon:mg3100_printer:-:*:*:*:*:*:*:*
cpe:2.3:h:canon:mg5300_printer:-:*:*:*:*:*:*:*
cpe:2.3:h:canon:mg6100_printer:-:*:*:*:*:*:*:*
cpe:2.3:h:canon:mp340_printer:-:*:*:*:*:*:*:*
cpe:2.3:h:canon:mp495_printer:-:*:*:*:*:*:*:*
cpe:2.3:h:canon:mx870_printer:-:*:*:*:*:*:*:*
cpe:2.3:h:canon:mx890_printer:-:*:*:*:*:*:*:*
cpe:2.3:h:canon:mx920_printer:-:*:*:*:*:*:*:*
cpe:2.3:h:canon:mx922_printer:-:*:*:*:*:*:*:*

History

21 Nov 2024, 01:55

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/fulldisclosure/2013-06/0146.html - () http://archives.neohapsis.com/archives/fulldisclosure/2013-06/0146.html -
References () http://www.mattandreko.com/2013/06/canon-y-u-no-security.html - () http://www.mattandreko.com/2013/06/canon-y-u-no-security.html -
References () https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/canon_wireless.rb - () https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/canon_wireless.rb -

Information

Published : 2013-06-21 21:55

Updated : 2024-11-21 01:55


NVD link : CVE-2013-4614

Mitre link : CVE-2013-4614

CVE.ORG link : CVE-2013-4614


JSON object : View

Products Affected

canon

  • mg5300_printer
  • mx920_printer
  • mg3100_printer
  • mx922_printer
  • mx890_printer
  • mp495_printer
  • mp340_printer
  • mg6100_printer
  • mx870_printer
CWE
CWE-255

Credentials Management Errors