Vulnerability Description
The FTP print feature in multiple Canon printers, including imageRUNNER and imagePRESS, allow remote attackers to use the server as an inadvertent proxy via a modified PORT command, aka FTP bounce.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canon | I-Sensys | lbp3360 |
| Canon | Imagepress | c1 |
| Canon | Imagerunner | 85plus |
| Canon | Imagerunner 2620 | All versions |
| Canon | Imagerunner 5000I | All versions |
| Canon | Imagerunner 5020 | All versions |
| Canon | Imagerunner 6870 | All versions |
| Canon | Imagerunner 8500 | All versions |
| Canon | Imagerunner 9070 | All versions |
| Canon | Imagerunner C3200 | All versions |
| Canon | Imagerunner C3220 | All versions |
| Canon | Imagerunner C6800 | All versions |
References
- http://itso.iu.edu/20080229_Canon_MFD_FTP_bounce_attack
- http://jvn.jp/en/jp/JVN10056705/index.html
- http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000013.html
- http://securitytracker.com/id?1019528
- http://www.kb.cert.org/vuls/id/568073US Government Resource
- http://www.securityfocus.com/bid/28042
- http://www.usa.canon.com/html/security/pdf/CVA-001.pdf
- http://itso.iu.edu/20080229_Canon_MFD_FTP_bounce_attack
- http://jvn.jp/en/jp/JVN10056705/index.html
- http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000013.html
- http://securitytracker.com/id?1019528
- http://www.kb.cert.org/vuls/id/568073US Government Resource
- http://www.securityfocus.com/bid/28042
- http://www.usa.canon.com/html/security/pdf/CVA-001.pdf
FAQ
What is CVE-2008-0303?
CVE-2008-0303 is a vulnerability with a CVSS score of 6.4 (MEDIUM). The FTP print feature in multiple Canon printers, including imageRUNNER and imagePRESS, allow remote attackers to use the server as an inadvertent proxy via a modified PORT command, aka FTP bounce.
How severe is CVE-2008-0303?
CVE-2008-0303 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-0303?
Check the references section above for vendor advisories and patch information. Affected products include: Canon I-Sensys, Canon Imagepress, Canon Imagerunner, Canon Imagerunner 2620, Canon Imagerunner 5000I.