3.5
CVSSv2

CVE-2021-20877

Published: 08/02/2022 Updated: 14/02/2022
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series (MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series (LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS (LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER (2206IF, 2204N, and 2204F) sold in Europe) allows remote malicious users to inject an arbitrary script via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

canon 2204f -

canon 2204n -

canon 2206if -

canon lbp113w -

canon lbp151dw -

canon lbp162 -

canon lbp162dw -

canon lbp162l -

canon mf113w -

canon mf212w -

canon mf217w -

canon mf222dw -

canon mf224dw -

canon mf227dw -

canon mf229dw -

canon mf232w -

canon mf237w -

canon mf242dw -

canon mf244dw -

canon mf245dw -

canon mf247dw -

canon mf249dw -

canon mf262dw -

canon mf264dw -

canon mf265dw -

canon mf267dw -

canon mf269dw -

canon mf269dw vp -

canon mf4570dn -

canon mf4570dw -

canon mf4770n -

canon mf4780w -

canon mf4880dw -

canon mf4890dw -