SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-14339

This allows an attacker's malicious application to obtain sensitive information including factory passwords for the administrator web interface and WPA2-PSK key.

MEDIUM 5.5EPSS 5.39%

Does this matter?

Lower severity and a low EPSS score (5.39%). Track it; it rarely justifies an emergency change on its own.

Description

The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly restrict canon.ij.printer.capability.data data access. This allows an attacker's malicious application to obtain sensitive information including factory passwords for the administrator web interface and WPA2-PSK key.

CVSS 3.0
5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS
5.39% probability · 92th percentile
CISA KEV
Not listed
Affected
canon/print
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.