VulnerabilityModified
CVE-2008-0303
The FTP print feature in multiple Canon printers, including imageRUNNER and imagePRESS, allow remote attackers to use the server as an inadvertent proxy via a modified PORT command, aka FTP bounce.
MEDIUM 6.4EPSS 2.05%
Does this matter?
Lower severity and a low EPSS score (2.05%). Track it; it rarely justifies an emergency change on its own.
Description
The FTP print feature in multiple Canon printers, including imageRUNNER and imagePRESS, allow remote attackers to use the server as an inadvertent proxy via a modified PORT command, aka FTP bounce.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
- EPSS
- 2.05% probability · 80th percentile
- CISA KEV
- Not listed
- Affected
- canon/i-sensys · canon/imagepress · canon/imagerunner · canon/imagerunner 2620 · canon/imagerunner 5000i · canon/imagerunner 5020 · canon/imagerunner 6870 · canon/imagerunner 8500 · canon/imagerunner 9070 · canon/imagerunner c3200 · canon/imagerunner c3220 · canon/imagerunner c6800
- Source
- cve@mitre.org
References
- http://itso.iu.edu/20080229_Canon_MFD_FTP_bounce_attack
- http://jvn.jp/en/jp/JVN10056705/index.html
- http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000013.html
- http://securitytracker.com/id?1019528
- http://www.kb.cert.org/vuls/id/568073US Government Resource
- http://www.securityfocus.com/bid/28042
- http://www.usa.canon.com/html/security/pdf/CVA-001.pdf
- http://itso.iu.edu/20080229_Canon_MFD_FTP_bounce_attack
- http://jvn.jp/en/jp/JVN10056705/index.html
- http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000013.html
- http://securitytracker.com/id?1019528
- http://www.kb.cert.org/vuls/id/568073US Government Resource
- http://www.securityfocus.com/bid/28042
- http://www.usa.canon.com/html/security/pdf/CVA-001.pdf
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.