In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver can be used for clickjacking. This includes the settings page.
References
Link Resource
https://kth.diva-portal.org/smash/get/diva2:1623489/FULLTEXT01.pdf Technical Description Third Party Advisory
https://ultimaker.com/3d-printers/ultimaker-s3 Product Vendor Advisory
https://ultimaker.com/3d-printers/ultimaker-s5 Product Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-01-10T01:10:25

Updated: 2022-01-10T01:10:25

Reserved: 2021-06-07T00:00:00


Link: CVE-2021-34087

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-01-10T14:10:17.613

Modified: 2022-01-14T15:09:40.093


Link: CVE-2021-34087

JSON object: View

cve-icon Redhat Information

No data.

CWE