CVE-2019-5995 is a missing authorization vulnerability affecting numerous Canon EOS series digital cameras and select PowerShot models. This flaw allows for the installation of malicious or unofficial firmware updates without user consent, potentially via an unspecified network vector. Rated 6.5 Medium (CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N), it indicates an attacker on the adjacent network could exploit this with low complexity to impact the integrity of the device. While there is no known public exploit code or active exploitation listed in KEV, the vulnerability has garnered significant community discussion and media coverage, including demonstrations of ransomware attacks on affected cameras.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.1.0CPE matchmatch criteria | cpe:2.3:o:canon:eos-1d_x_firmware:*:*:*:*:*:*:*:* | ||
<= 1.1.6CPE matchmatch criteria | cpe:2.3:o:canon:eos-1d_x_mkii_firmware:*:*:*:*:*:*:*:* | ||
<= 1.4.1CPE matchmatch criteria | cpe:2.3:o:canon:eos-1d_c_firmware:*:*:*:*:*:*:*:* | ||
<= 1.3.5CPE matchmatch criteria | cpe:2.3:o:canon:eos_5d_mark_iii_firmware:*:*:*:*:*:*:*:* | ||
<= 1.2.0CPE matchmatch criteria | cpe:2.3:o:canon:eos_5d_mark_iv_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.