CVE-2023-0857Incorrect User Management in I-sensys Lbp621cw Firmware

Severity
7.5HIGHNVD
CNA5.9
EPSS
0.1%
top 75.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 11

Description

Unintentional change of settings during initial registration of system administrators which uses control protocols. The affected Office / Small Office Multifunction Printers and Laser Printers(*) may allow an attacker on the network segment to trigger unauthorized access to the product. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C fi

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages46 packages

CVEListV5canon_inc/canon_office_small_office_multifunction_printers_and_laser_printersSatera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier sold in US. i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF, C1127i firmware Ver.11.04 and earlier sold in Europe.

🔴Vulnerability Details

2
GHSA
GHSA-p555-r2hc-6428: Unintentional change of settings during initial registration of system administrators which uses control protocols2023-05-11
CVEList
CVE-2023-0857: Unintentional change of settings during initial registration of system administrators which uses control protocols2023-05-11
CVE-2023-0857 — Incorrect User Management | cvebase