CVE-2021-34087

In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver can be used for clickjacking. This includes the settings page.
References
Link Resource
https://kth.diva-portal.org/smash/get/diva2:1623489/FULLTEXT01.pdf Technical Description Third Party Advisory
https://ultimaker.com/3d-printers/ultimaker-s3 Product Vendor Advisory
https://ultimaker.com/3d-printers/ultimaker-s5 Product Vendor Advisory
Configurations

Configuration 1


Information

Published : 2022-01-10 02:10

Updated : 2022-01-14 03:09


NVD link : CVE-2021-34087

Mitre link : CVE-2021-34087

Products Affected
No products.
CWE
CWE-1021

Improper Restriction of Rendered UI Layers or Frames