The Canon Oce Colorwave 500 4.0.0.0 printer's web application is missing any form of CSRF protections. This is a system-wide issue. An attacker could perform administrative actions by targeting a logged-in administrative user. NOTE: this is fixed in the latest version.
2020-03-19T19:15:11.990
2024-11-21T04:55:48.910
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | canon | oce_colorwave_500_firmware | ≤ 4.0.0.0 | Yes |
Hardware | canon | oce_colorwave_500 | - | No |