Login

20080229 Canon MFD FTP bounce attack

Indiana University Security Advisory:

Canon Multi Function Devices vulnerable to FTP bounce attack.

Advisory ID:

20080229 Canon MFD FTP bounce attack

Advisory revisions:

Credit/acknowledgement:

CVE-2008-0303

Summary:

Certain Canon Multi Function Devices (see Products affected below) allow remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command, a variant of CVE-1999-0017.

Mitigation/workarounds:

Firmware updates that fix the vulnerability are available, but are not user installable. They require a service technician call. If one of the above two workarounds are not sufficient, please contact your local Canon Authorized Service Dealer.

Additionally, best practices suggest that access controls and network firewall policies be put into place to only allow connections from trusted machines and networks.

Criticality:

This vulnerability has a risk of not critical.

Products affected:

References: