HIGH · 7.5

CVE-2020-16849

An issue was discovered on Canon MF237w 06.07 devices. An "Improper Handling of Length Parameter Inconsistency" issue in the IPv4/ICMPv4 component, when handling a packet sent by an unauthenticated ne...

Vulnerability Description

An issue was discovered on Canon MF237w 06.07 devices. An "Improper Handling of Length Parameter Inconsistency" issue in the IPv4/ICMPv4 component, when handling a packet sent by an unauthenticated network attacker, may expose Sensitive Information.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
CanonMf237W Firmware06.07
CanonMf237W-
CanonMf113W Firmware-
CanonMf113W-
CanonMf212W Firmware-
CanonMf212W-
CanonMf216N Firmware-
CanonMf216N-
CanonMf217W Firmware-
CanonMf217W-
CanonMf226Dn Firmware-
CanonMf226Dn-
CanonMf229Dw Firmware-
CanonMf229Dw-
CanonMf231 Firmware-
CanonMf231-
CanonMf232W Firmware-
CanonMf232W-
CanonMf244Dw Firmware-
CanonMf244Dw-

References

FAQ

What is CVE-2020-16849?

CVE-2020-16849 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered on Canon MF237w 06.07 devices. An "Improper Handling of Length Parameter Inconsistency" issue in the IPv4/ICMPv4 component, when handling a packet sent by an unauthenticated ne...

How severe is CVE-2020-16849?

CVE-2020-16849 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-16849?

Check the references section above for vendor advisories and patch information. Affected products include: Canon Mf237W Firmware, Canon Mf237W, Canon Mf113W Firmware, Canon Mf113W, Canon Mf212W Firmware.