VulnerabilityModified
CVE-2019-14339
This allows an attacker's malicious application to obtain sensitive information including factory passwords for the administrator web interface and WPA2-PSK key.
MEDIUM 5.5EPSS 5.39%
Does this matter?
Lower severity and a low EPSS score (5.39%). Track it; it rarely justifies an emergency change on its own.
Description
The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly restrict canon.ij.printer.capability.data data access. This allows an attacker's malicious application to obtain sensitive information including factory passwords for the administrator web interface and WPA2-PSK key.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 5.39% probability · 92th percentile
- CISA KEV
- Not listed
- Affected
- canon/print
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/154266/Canon-PRINT-2.5.5-URI-Injection.htmlExploit, Third Party Advisory, VDB Entry
- https://play.google.com/store/apps/details?id=jp.co.canon.bsd.ad.pixmaprint&hl=en_USProduct, Third Party Advisory
- http://packetstormsecurity.com/files/154266/Canon-PRINT-2.5.5-URI-Injection.htmlExploit, Third Party Advisory, VDB Entry
- https://play.google.com/store/apps/details?id=jp.co.canon.bsd.ad.pixmaprint&hl=en_USProduct, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.