Vulnerability Description
Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series (MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series (LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS (LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER (2206IF, 2204N, and 2204F) sold in Europe) allows remote attackers to inject an arbitrary script via unspecified vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canon | 2204F | - |
| Canon | 2204N | - |
| Canon | 2206If | - |
| Canon | Lbp113W | - |
| Canon | Lbp151Dw | - |
| Canon | Lbp162 | - |
| Canon | Lbp162Dw | - |
| Canon | Lbp162L | - |
| Canon | Mf113W | - |
| Canon | Mf212W | - |
| Canon | Mf217W | - |
| Canon | Mf222Dw | - |
| Canon | Mf224Dw | - |
| Canon | Mf227Dw | - |
| Canon | Mf229Dw | - |
| Canon | Mf232W | - |
| Canon | Mf237W | - |
| Canon | Mf242Dw | - |
| Canon | Mf244Dw | - |
| Canon | Mf245Dw | - |
Related Weaknesses (CWE)
References
- https://cweb.canon.jp/e-support/info/211221xss.htmlVendor Advisory
- https://jvn.jp/en/jp/JVN64806328/index.htmlThird Party Advisory
- https://jvn.jp/jp/JVN64806328/index.htmlThird Party Advisory
- https://www.canon-europe.com/support/product-security-latest-news/Vendor Advisory
- https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detVendor Advisory
- https://cweb.canon.jp/e-support/info/211221xss.htmlVendor Advisory
- https://jvn.jp/en/jp/JVN64806328/index.htmlThird Party Advisory
- https://jvn.jp/jp/JVN64806328/index.htmlThird Party Advisory
- https://www.canon-europe.com/support/product-security-latest-news/Vendor Advisory
- https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detVendor Advisory
FAQ
What is CVE-2021-20877?
CVE-2021-20877 is a vulnerability with a CVSS score of 4.8 (MEDIUM). Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w,...
How severe is CVE-2021-20877?
CVE-2021-20877 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-20877?
Check the references section above for vendor advisories and patch information. Affected products include: Canon 2204F, Canon 2204N, Canon 2206If, Canon Lbp113W, Canon Lbp151Dw.