CVE-2021-20877
Summary
| CVE | CVE-2021-20877 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-08 11:15:00 UTC |
| Updated | 2022-02-14 21:07:00 UTC |
| Description | Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series (MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series (LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS (LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER (2206IF, 2204N, and 2204F) sold in Europe) allows remote attackers to inject an arbitrary script via unspecified vectors. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Canon | 2204f | - | All | All | All |
| Hardware | Canon | 2204n | - | All | All | All |
| Hardware | Canon | 2206if | - | All | All | All |
| Hardware | Canon | Lbp113w | - | All | All | All |
| Hardware | Canon | Lbp151dw | - | All | All | All |
| Hardware | Canon | Lbp162 | - | All | All | All |
| Hardware | Canon | Lbp162dw | - | All | All | All |
| Hardware | Canon | Lbp162l | - | All | All | All |
| Hardware | Canon | Mf113w | - | All | All | All |
| Hardware | Canon | Mf212w | - | All | All | All |
| Hardware | Canon | Mf217w | - | All | All | All |
| Hardware | Canon | Mf222dw | - | All | All | All |
| Hardware | Canon | Mf224dw | - | All | All | All |
| Hardware | Canon | Mf227dw | - | All | All | All |
| Hardware | Canon | Mf229dw | - | All | All | All |
| Hardware | Canon | Mf232w | - | All | All | All |
| Hardware | Canon | Mf237w | - | All | All | All |
| Hardware | Canon | Mf242dw | - | All | All | All |
| Hardware | Canon | Mf244dw | - | All | All | All |
| Hardware | Canon | Mf245dw | - | All | All | All |
| Hardware | Canon | Mf247dw | - | All | All | All |
| Hardware | Canon | Mf249dw | - | All | All | All |
| Hardware | Canon | Mf262dw | - | All | All | All |
| Hardware | Canon | Mf264dw | - | All | All | All |
| Hardware | Canon | Mf265dw | - | All | All | All |
| Hardware | Canon | Mf267dw | - | All | All | All |
| Hardware | Canon | Mf269dw | - | All | All | All |
| Hardware | Canon | Mf269dw Vp | - | All | All | All |
| Hardware | Canon | Mf4570dn | - | All | All | All |
| Hardware | Canon | Mf4570dw | - | All | All | All |
| Hardware | Canon | Mf4770n | - | All | All | All |
| Hardware | Canon | Mf4780w | - | All | All | All |
| Hardware | Canon | Mf4880dw | - | All | All | All |
| Hardware | Canon | Mf4890dw | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Canon U.S.A., Inc. | Product Advisory Detail Page | MISC | www.usa.canon.com | |
| JVN#64806328: Canon laser printers and small office multifunctional printers vulnerable to cross-site scripting | MISC | jvn.jp | |
| キヤノン:サポート|レーザープリンター及びスモールオフィス向け複合機のクロスサイトスクリプティングに関する脆弱性対応について | MISC | cweb.canon.jp | |
| www.canon-europe.com/support/product-security-latest-news | MISC | www.canon-europe.com | |
| JVN#64806328: キヤノン製レーザープリンターおよびスモールオフィス向け複合機におけるクロスサイトスクリプティングの脆弱性 | MISC | jvn.jp | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.