The default configuration of the administrative interface on the Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers does not require authentication, which allows remote attackers to modify the configuration by visiting the Advanced page. NOTE: the vendor has apparently responded by stating "for user convenience, the default setting does not require a password. However, if a user has a particular concern about third parties accessing the user's home printer, the default setting can be changed to add a password."

Project Subscriptions

Vendors Products
Mg3100 Printer Subscribe
Mg5300 Printer Subscribe
Mg6100 Printer Subscribe
Mp340 Printer Subscribe
Mp495 Printer Subscribe
Mx870 Printer Subscribe
Mx890 Printer Subscribe
Mx920 Printer Subscribe
Mx922 Printer Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2013-4469 The default configuration of the administrative interface on the Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers does not require authentication, which allows remote attackers to modify the configuration by visiting the Advanced page. NOTE: the vendor has apparently responded by stating "for user convenience, the default setting does not require a password. However, if a user has a particular concern about third parties accessing the user's home printer, the default setting can be changed to add a password."
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-16T17:27:45.686Z

Reserved: 2013-06-17T00:00:00Z

Link: CVE-2013-4613

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2013-06-21T21:55:01.007

Modified: 2025-04-11T00:51:21.963

Link: CVE-2013-4613

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses