Back to Database
Status published
Medium
CVE-2008-0303
The FTP print feature in multiple Canon printers, including imageRUNNER...
Vulnerability Description
The FTP print feature in multiple Canon printers, including imageRUNNER and imagePRESS, allow remote attackers to use the server as an inadvertent proxy via a modified PORT command, aka FTP bounce.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-0303
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.kb.cert.org/vuls/id/568073
- http://www.securityfocus.com/bid/28042
- http://jvn.jp/en/jp/JVN10056705/index.html
- http://itso.iu.edu/20080229_Canon_MFD_FTP_bounce_attack
- http://securitytracker.com/id?1019528
- http://www.usa.canon.com/html/security/pdf/CVA-001.pdf
- http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000013.html
More from canon
View All →CVE-2022-38765
Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce...
Unknown
0
CVE-2022-37461
Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View...
Unknown
0
CVE-2022-26111
The BeanShell components of IRISNext through 9.8.28 allow execution of...
High
8.8
CVE-2021-43471
In Canon LBP223 printers, the System Manager Mode login does...
High
7.5
CVE-2021-39368
Canon Oce Print Exec Workgroup 1.3.2 allows XSS via the...
Medium
6.1
Affected Vendor
canon
View all reports →Affected Software
i-sensys, imagepress, imagerunner, imagerunner 2620, imagerunner 5000i, imagerunner 5020, imagerunner 6870, imagerunner 8500, imagerunner 9070, imagerunner c3200, imagerunner c3220, imagerunner c6800
Vulnerable Versions:
lbp3360, lbp3460, lbp5360, c1, 85plus, 105plus, 2230, 2270, 2570c, 2570ci, 2870, 3025, 3025n, 3035, 3035n, 3045, 3045n, 3170c, 3170ci, 3180c, 3180ci, 3530, 3570, 4570, 5055, 5055n, 5065, 5065n, 5075, 5075n, 5570, 5800c, 5800cn, 6570, 6800c, 6800cn, 7086, 7095, 7095p, 7105, 8070, c2380i, c2620, c2620n, c2880, c2880i, c3220n, c3380, c3380i, c4080i, c4580i, c5185i, c5870, c5870i, c5880, c5880i, c6870i, c6880, c6880i, clc4040, clc5151
Timeline
Official Publish:
February 29th, 2008
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.