CVE-2018-11692

An issue was discovered on Canon LBP6650, LBP3370, LBP3460, and LBP7750C devices. It is possible to bypass the Administrator Mode authentication for /tlogin.cgi via vectors involving frame.cgi?page=DevStatus. NOTE: the vendor reportedly responded that this issue occurs when a customer keeps the default settings without using the countermeasures and best practices shown in the documentation
References
Link Resource
https://gist.github.com/huykha/2dfbe97810e96a05e67359fd9e7cc9ff Broken Link Third Party Advisory
https://www.exploit-db.com/exploits/44844/ Broken Link Third Party Advisory VDB Entry
https://gist.github.com/huykha/2dfbe97810e96a05e67359fd9e7cc9ff Broken Link Third Party Advisory
https://www.exploit-db.com/exploits/44844/ Broken Link Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:canon:lbp3370_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:canon:lbp3370:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:canon:lbp3460_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:canon:lbp3460:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:canon:lbp7750c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:canon:lbp7750c:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:canon:lbp6650_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:canon:lbp6650:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:43

Type Values Removed Values Added
References () https://gist.github.com/huykha/2dfbe97810e96a05e67359fd9e7cc9ff - Broken Link, Third Party Advisory () https://gist.github.com/huykha/2dfbe97810e96a05e67359fd9e7cc9ff - Broken Link, Third Party Advisory
References () https://www.exploit-db.com/exploits/44844/ - Broken Link, Third Party Advisory, VDB Entry () https://www.exploit-db.com/exploits/44844/ - Broken Link, Third Party Advisory, VDB Entry

07 Nov 2023, 02:51

Type Values Removed Values Added
Summary ** DISPUTED ** An issue was discovered on Canon LBP6650, LBP3370, LBP3460, and LBP7750C devices. It is possible to bypass the Administrator Mode authentication for /tlogin.cgi via vectors involving frame.cgi?page=DevStatus. NOTE: the vendor reportedly responded that this issue occurs when a customer keeps the default settings without using the countermeasures and best practices shown in the documentation. An issue was discovered on Canon LBP6650, LBP3370, LBP3460, and LBP7750C devices. It is possible to bypass the Administrator Mode authentication for /tlogin.cgi via vectors involving frame.cgi?page=DevStatus. NOTE: the vendor reportedly responded that this issue occurs when a customer keeps the default settings without using the countermeasures and best practices shown in the documentation

Information

Published : 2018-06-04 06:29

Updated : 2024-11-21 03:43


NVD link : CVE-2018-11692

Mitre link : CVE-2018-11692

CVE.ORG link : CVE-2018-11692


JSON object : View

Products Affected

canon

  • lbp6650
  • lbp3370_firmware
  • lbp7750c
  • lbp3460
  • lbp6650_firmware
  • lbp7750c_firmware
  • lbp3460_firmware
  • lbp3370
CWE
CWE-287

Improper Authentication