CVE-2018-12049
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
08/06/2018
Last modified:
05/08/2024
Description
A remote attacker can bypass the System Manager Mode on the Canon LBP6030w web interface without a PIN for /checkLogin.cgi via vectors involving /portal_top.html to get full access to the device. NOTE: the vendor reportedly responded that this issue occurs when a customer keeps the default settings without using the countermeasures and best practices shown in the documentation
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:canon:lbp6030w_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:canon:lbp6030w:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



