Vulnerabilities > CVE-2019-14339 - Unspecified vulnerability in Canon Print 2.5.5

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
local
low complexity
canon
exploit available

Summary

The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly restrict canon.ij.printer.capability.data data access. This allows an attacker's malicious application to obtain sensitive information including factory passwords for the administrator web interface and WPA2-PSK key.

Vulnerable Configurations

Part Description Count
Application
Canon
1

Exploit-Db

idEDB-ID:47321
last seen2019-08-30
modified2019-08-30
published2019-08-30
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/47321
titleCanon PRINT 2.5.5 - Information Disclosure

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/154266/canonprint255-inject.txt
idPACKETSTORM:154266
last seen2019-08-31
published2019-08-30
reporter0x48piraj
sourcehttps://packetstormsecurity.com/files/154266/Canon-PRINT-2.5.5-URI-Injection.html
titleCanon PRINT 2.5.5 URI Injection