peter bassill · operator
$ cve CVE-2019-14339 JSON

CVE-2019-14339 EXPLOIT

5.5
MEDIUM · CVSS 3.0 · EPSS 5.4% (pctl 92)

Patch early

A public exploit exists.

Description

The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly restrict canon.ij.printer.capability.data data access. This allows an attacker's malicious application to obtain sensitive information including factory passwords for the administrator web interface and WPA2-PSK key.

Scoring

CVSS5.5 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS5.39% — more likely to be exploited than 92% of all CVEs
On CISA KEVno
Public exploityes
Published2019-09-05
Last modified2026-06-17

Affected (1)

VendorProduct
canonprint

Public exploits

SourceTitleDate
exploit-dbCanon PRINT 2.5.5 - Information Disclosure2019-08-30

References

→ the Explorer  ·  watch your stack  ·  NVD