CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-3079: A passback vulnerability which relates to office/small office multifunction printers and laser printers.

6.3 CVSS

Description

A passback vulnerability which relates to office/small office multifunction printers and laser printers.

Classification

CVE ID: CVE-2025-3079

CVSS Base Severity: MEDIUM

CVSS Base Score: 6.3

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N

Problem Types

CWE-522: Insufficiently Protected Credentials

Affected Products

Vendor: Canon Inc.

Product: imageRUNNER Series, imageCLASS Series, i-sensys Series, Satera Series

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.11% (scored less or equal to compared to others)

EPSS Date: 2025-06-17 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-3079
https://psirt.canon/advisory-information/cp2025-004/
https://canon.jp/support/support-info/250519vulnerability-response
https://www.usa.canon.com/about-us/to-our-customers/cp2025-004-vulnerability-mitigation-remediation-for-production-printers-office-small-office-multifunction-printers-laser-printers
https://www.canon-europe.com/support/product-security/
https://psirt.canon/hardening/
https://corporate.jp.canon/caution/160106

Timeline