Vulnerability Description
In Canon LBP223 printers, the System Manager Mode login does not require an account password or PIN. An attacker can remotely shut down the device after entering the background, creating a denial of service vulnerability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canon | Lbp223Dw Firmware | - |
| Canon | Lbp223Dw | - |
Related Weaknesses (CWE)
References
- https://github.com/cxaqhq/cve-1ExploitThird Party Advisory
- https://github.com/cxaqhq/cve-1ExploitThird Party Advisory
FAQ
What is CVE-2021-43471?
CVE-2021-43471 is a vulnerability with a CVSS score of 7.5 (HIGH). In Canon LBP223 printers, the System Manager Mode login does not require an account password or PIN. An attacker can remotely shut down the device after entering the background, creating a denial of s...
How severe is CVE-2021-43471?
CVE-2021-43471 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-43471?
Check the references section above for vendor advisories and patch information. Affected products include: Canon Lbp223Dw Firmware, Canon Lbp223Dw.