V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2021-43471
CVE
HighConfirmedExploit available

In Canon LBP223 printers, the System Manager Mode login does not require an account password or PIN. An attacker can remotely shut down the…

CVSS
7.5
High
EPSS
0.00
p52
Published
2021-01-01
Updated
2021-01-01
Description

In Canon LBP223 printers, the System Manager Mode login does not require an account password or PIN. An attacker can remotely shut down the device after entering the background, creating a denial of service vulnerability.

Tags · CWE
Pre-auth
CWE-521
CAPEC-16
CAPEC-49
CAPEC-55
CAPEC-70
CAPEC-112
CAPEC-509
CAPEC-555
CAPEC-561
CAPEC-565
Affected products
Lbp223dw_firmware
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Timeline
2021-01-01
Published
2021-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.003 · p52
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-555 · CWE-521
└ via CAPEC-561 · CWE-521
└ via CAPEC-70 · CWE-521
└ via CAPEC-112 · CWE-521
└ via CAPEC-49 · CWE-521
└ via CAPEC-55 · CWE-521
└ via CAPEC-565 · CWE-521
└ via CAPEC-555 · CWE-521
└ via CAPEC-555 · CWE-521
└ via CAPEC-509 · CWE-521
Known exploits — Сканер-ВС
CVE-2021-43471
github-poc · https://github.com/cxaqhq/CVE-2021-43471
Enterprise
Affected software
ProductVendorStatus
lbp223dw_firmware*Tracked
Source databases
CVE