packetstormsecurity.com
http://packetstormsecurity.com/files/154266/Canon-PRINT-2.5.5-URI-Injection.html CVE-2019-14339
MEDIUM
Canon PRINT 2.5.5 - Information Disclosure
Record summary
CVE-2019-14339 has a selected CVSS score of 5.5 (medium); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly restrict canon.ij.printer.capability.data data access. This allows an attacker's malicious application to obtain sensitive information including factory passwords for the administrator web interface and WPA2-PSK key.
Description source: CVE List
Exploitation context
Proofs of concept
2Catalogued exploits
ExploitDBCanon PRINT 2.5.5 - Information DisclosureExploitDB exploitby 0x48pirajNot analyzed1 file
Repository PoCs
GitHub0x48piraj/CVE-2019-14339Repository PoCby 0x48pirajStars: 14Not analyzed40 files
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-14339 play.google.com
https://play.google.com/store/apps/details?id=jp.co.canon.bsd.ad.pixmaprint&hl=en_US