U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2021-20877

Change History

Initial Analysis by NIST 2/14/2022 4:07:30 PM

Action Type Old Value New Value
Added CVSS V3.1

								
							
							
						
NIST AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Added CVSS V2

								
							
							
						
NIST (AV:N/AC:M/Au:S/C:N/I:P/A:N)
Added CWE

								
							
							
						
NIST CWE-79
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:h:canon:2204f:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:2204n:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:2206if:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:lbp113w:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:lbp151dw:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:lbp162:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:lbp162dw:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:lbp162l:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf113w:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf212w:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf217w:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf222dw:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf224dw:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf227dw:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf229dw:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf232w:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf237w:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf242dw:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf244dw:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf245dw:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf247dw:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf249dw:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf262dw:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf264dw:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf265dw:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf267dw:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf269dw:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf269dw_vp:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf4570dn:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf4570dw:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf4770n:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf4780w:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf4880dw:-:*:*:*:*:*:*:*
     *cpe:2.3:h:canon:mf4890dw:-:*:*:*:*:*:*:*
Changed Reference Type
https://cweb.canon.jp/e-support/info/211221xss.html No Types Assigned
https://cweb.canon.jp/e-support/info/211221xss.html Vendor Advisory
Changed Reference Type
https://jvn.jp/en/jp/JVN64806328/index.html No Types Assigned
https://jvn.jp/en/jp/JVN64806328/index.html Third Party Advisory
Changed Reference Type
https://jvn.jp/jp/JVN64806328/index.html No Types Assigned
https://jvn.jp/jp/JVN64806328/index.html Third Party Advisory
Changed Reference Type
https://www.canon-europe.com/support/product-security-latest-news/ No Types Assigned
https://www.canon-europe.com/support/product-security-latest-news/ Vendor Advisory
Changed Reference Type
https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/Service-Notice-Canon-Laser-Printer-and-Small-Office-Multifunctional-Printer-related-to-cross-site-scripting No Types Assigned
https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/Service-Notice-Canon-Laser-Printer-and-Small-Office-Multifunctional-Printer-related-to-cross-site-scripting Vendor Advisory
Added CVSS V2 Metadata

								
							
							
						
Victim must voluntarily interact with attack mechanism