what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Canon Printer DoS / Secret Disclosure

Canon Printer DoS / Secret Disclosure
Posted Jun 18, 2013
Authored by Matt Andreko

Various Canon printers suffer from a lack of password authentication, denial of service, and WEP/WPA/WPA2 secret disclosure vulnerabilities. Models affected include, but are not limited to, MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, and MX920.

tags | exploit, denial of service, vulnerability, info disclosure
advisories | CVE-2013-4613, CVE-2013-4614, CVE-2013-4615
SHA-256 | e6fe9b64dfedd1825acdce35d794eab613d2db78380ac3ba1cd3a4e3f484e8bc

Canon Printer DoS / Secret Disclosure

Change Mirror Download
The below 3 issues have been tested and verified working on the following
Canon Printer models (May affect more, but this is all I was able to test
against):
MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920

#1 (CVE-2013-4613): Canon printers do not require a password for the
administrative interfaces by default. Unauthorized users on the network may
configure the printer. If the printer is exposed to the public internet,
anonymous users may make configuration changes as well. This should be
corrected by requiring a password, even if only a default, but should
recommend users to change it upon initial setup of the device.

#2 (CVE-2013-4614): The administrative interface on these printers allow a
user to enter a WEP/WPA/WPA2 pre-shared key. Once a key is entered, when a
user browses the configuration page again, they can view the current
password in clear-text. Once a password is configured, it should not allow
the user to read it again. If the user wants to change the password, they
should be required to enter a new one, which then overwrites the old one.

#3 (CVE-2013-4615): There is a denial of service condition in the
administrative interface on the devices. Using specially crafted HTTP
requests, it is possible to cause the device to no longer respond. This
requires the device to be turned off, and then back on again, to which the
printer will display a message about not being properly turned off, on the
display (if model has a display).

I have disclosed all 3 of these issues to Canon, and unfortunately they do
not feel it is necessary to fix them (In all fairness, they're not super
high severity). More details, along with PoC and Metasploit modules are
available here: *
http://www.mattandreko.com/2013/06/canon-y-u-no-security.html*

Timeline:
May 27, 2013: Initial Email to vendor's support
May 28, 2013: Vendor support emailed for additional details
May 28, 2013: Sent a proof-of-concept exploit for the DoS vulnerability to
vendor
May 30, 2013: Vendor escalated issue internally
June 4, 2013: Vendor notification that issue has been escalated to
manufacturer
June 14, 2013: Vendor notification that they will not fix issues
June 18, 2013: Public Disclosure
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    28 Files
  • 16
    Jul 16th
    6 Files
  • 17
    Jul 17th
    34 Files
  • 18
    Jul 18th
    6 Files
  • 19
    Jul 19th
    34 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    19 Files
  • 23
    Jul 23rd
    17 Files
  • 24
    Jul 24th
    47 Files
  • 25
    Jul 25th
    31 Files
  • 26
    Jul 26th
    13 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    27 Files
  • 30
    Jul 30th
    49 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close