CVE-2004-2166 describes an unauthenticated print-from-email vulnerability in Canon ImageRUNNER 5000i and C3200 digital printers when IP address range filtering is not configured. This allows remote attackers to print arbitrary text by sending a text/plain email to TCP port 25. With a CVSS score of 7.5, this vulnerability is considered high severity due to its network attack vector, low attack complexity, and potential for partial confidentiality, integrity, and availability impact. There is no evidence of active exploitation, nor are there known Metasploit, Nuclei, or ExploitDB modules, though it has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:canon:imagerunner_5000i:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:canon:imagerunner_c3200:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.