Vulnerabilities > CVE-2004-2166 - Unspecified vulnerability in Canon Imagerunner 5000I and Imagerunner C3200

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
canon
nessus

Summary

The print-from-email feature in the Canon ImageRUNNER (iR) 5000i and C3200 digital printer, when not using IP address range filtering, allows remote attackers to print arbitrary text without authentication via a text/plain email to TCP port 25.

Vulnerable Configurations

Part Description Count
Application
Canon
2

Nessus

NASL familySMTP problems
NASL idCANON_PRINT_BY_SMTP.NASL
descriptionThe remote host seems to be a Canon ImageRUNNER printer, which runs a SMTP service. It is possible to send an email to the SMTP service and have it printed out. An attacker may use this flaw to send an endless stream of emails to the remote device and cause a denial of service by using all of the print paper.
last seen2020-06-01
modified2020-06-02
plugin id14819
published2004-09-24
reporterThis script is Copyright (C) 2004-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/14819
titleCanon ImageRUNNER SMTP Arbitrary Content Printing