MEDIUM · 5.0

CVE-2013-4615

The Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers allow remote attackers to cause a denial of service (device hang) via a crafted LAN_TXT24 parameter to English/p...

Vulnerability Description

The Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers allow remote attackers to cause a denial of service (device hang) via a crafted LAN_TXT24 parameter to English/pages_MacUS/cgi_lan.cgi followed by a direct request to English/pages_MacUS/lan_set_content.html. NOTE: the vendor has apparently responded by stating "Canon believes that its printers will not have to deal with unauthorized access to the network from an external location as long as the printers are used in a secured environment."

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
CanonMg3100 Printer-
CanonMg5300 Printer-
CanonMg6100 Printer-
CanonMp340 Printer-
CanonMp495 Printer-
CanonMx870 Printer-
CanonMx890 Printer-
CanonMx920 Printer-
CanonMx922 Printer-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-4615?

CVE-2013-4615 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers allow remote attackers to cause a denial of service (device hang) via a crafted LAN_TXT24 parameter to English/p...

How severe is CVE-2013-4615?

CVE-2013-4615 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-4615?

Check the references section above for vendor advisories and patch information. Affected products include: Canon Mg3100 Printer, Canon Mg5300 Printer, Canon Mg6100 Printer, Canon Mp340 Printer, Canon Mp495 Printer.