SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-4613

The default configuration of the administrative interface on the Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers does not require authentication, which allows remote attackers to modify the configuration by visiting…

HIGH 7.5EPSS 2.01%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.01%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The default configuration of the administrative interface on the Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers does not require authentication, which allows remote attackers to modify the configuration by visiting the Advanced page. NOTE: the vendor has apparently responded by stating "for user convenience, the default setting does not require a password. However, if a user has a particular concern about third parties accessing the user's home printer, the default setting can be changed to add a password."

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
2.01% probability · 80th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
canon/mg3100 printer · canon/mg5300 printer · canon/mg6100 printer · canon/mp340 printer · canon/mp495 printer · canon/mx870 printer · canon/mx890 printer · canon/mx920 printer · canon/mx922 printer
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.