4.8

CVE-2021-20877

Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series (MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series (LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS (LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER (2206IF, 2204N, and 2204F) sold in Europe) allows remote attackers to inject an arbitrary script via unspecified vectors.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Canon2204f Version-
Canon2204n Version-
Canon2206if Version-
CanonLbp113w Version-
CanonLbp151dw Version-
CanonLbp162 Version-
CanonLbp162dw Version-
CanonLbp162l Version-
CanonMf113w Version-
CanonMf212w Version-
CanonMf217w Version-
CanonMf222dw Version-
CanonMf224dw Version-
CanonMf227dw Version-
CanonMf229dw Version-
CanonMf232w Version-
CanonMf237w Version-
CanonMf242dw Version-
CanonMf244dw Version-
CanonMf245dw Version-
CanonMf247dw Version-
CanonMf249dw Version-
CanonMf262dw Version-
CanonMf264dw Version-
CanonMf265dw Version-
CanonMf267dw Version-
CanonMf269dw Version-
CanonMf269dw Vp Version-
CanonMf4570dn Version-
CanonMf4570dw Version-
CanonMf4770n Version-
CanonMf4780w Version-
CanonMf4880dw Version-
CanonMf4890dw Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.49
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.8 1.7 2.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.