CVE-2021-34087

In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver can be used for clickjacking. This includes the settings page.

Summary:

In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver can be used for clickjacking. This includes the settings page.

Reference Links(if available):

  • https://kth.diva-portal.org/smash/get/diva2:1623489/FULLTEXT01.pdf
  • https://ultimaker.com/3d-printers/ultimaker-s3
  • https://ultimaker.com/3d-printers/ultimaker-s5
  • CVSS Score (if available)

    v2: / HIGH

    v3: /

    Links to Exploits(if available)