CVE-2025-3078 Details
Description
A passback vulnerability which relates to production printers and office multifunction printers.
A passback vulnerability has been identified in Canon's office multifunction printers, small office multifunction printers, laser beam printers, and production printers. This vulnerability could allow an attacker who gains administrative access to the device to retrieve sensitive authentication information, such as SMTP or LDAP credentials, from the printer's settings.
Users are advised to change default passwords, set up administrator and general user ID/passwords where applicable, and ensure physical security of the devices. Additionally, some models have received firmware updates to enhance security; users should consult the Canon security guide for their specific product to determine if an update is available.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 20, 2025CISA-ADP
Assessed May 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://canon.jp/support/support-info/250519vulnerability-response | Canon Inc. | AdvisoryBundleRemedyVendor |
| https://corporate.jp.canon/caution/160106 | Canon Inc. | Technical DescriptionVendor |
| https://psirt.canon/advisory-information/cp2025-004/ | Canon Inc. | AdvisoryPermission RequiredVendor |
| https://psirt.canon/hardening/ | Canon Inc. | Permission RequiredVendor |
| https://www.canon-europe.com/support/product-security | Canon Inc. | Permission RequiredVendor |
| https://www.usa.canon.com/about-us/to-our-customers/cp2025-004-vulnerability-mitigation-remediation-for-production-printers-office-small-office-multifunction-printers-laser-printers | Canon Inc. | Permission RequiredVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | Canon Inc. |
Affected Products
| Product | Versions |
|---|---|
| Canon imageRUNNER ADVANCE | All versions |
CPE
Remediation
| |
| Canon imageRUNNER | All versions |
CPE
Remediation
| |
| Canon imagePRESS V | All versions |
CPE
Remediation
| |
| Canon imagePRESS | All versions |
CPE
Remediation
| |
| Canon Satera | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Canon Inc. |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 20, 2025 | New CVE Received | Canon Inc. |
Volerion