CVE-2018-11692
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
04/06/2018
Last modified:
05/08/2024
Description
An issue was discovered on Canon LBP6650, LBP3370, LBP3460, and LBP7750C devices. It is possible to bypass the Administrator Mode authentication for /tlogin.cgi via vectors involving frame.cgi?page=DevStatus. NOTE: the vendor reportedly responded that this issue occurs when a customer keeps the default settings without using the countermeasures and best practices shown in the documentation
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:canon:lbp3370_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:canon:lbp3370:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:canon:lbp3460_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:canon:lbp3460:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:canon:lbp7750c_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:canon:lbp7750c:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:canon:lbp6650_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:canon:lbp6650:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



