Canon PSIRT Logo

Canon Hardening Guides

Canon Hardening Guides

Updated: July 31, 2023
September 30, 2022
 
 

Securing products when connecting to a network

 
Many products and their various functions can be used more conveniently by connecting to a network. However, connecting products to a network introduces the possibility of security risks such as unauthorized access by malicious third parties.
 
For example, if a product is connected to a network with a default password or a password that is easy to guess, there is a risk of undesired changes to settings or data extraction. In addition, connecting a product to the internet without using a wired router or Wi-Fi router poses a greater risk of unauthorized access.
 
In order to minimize the risk of security issues, it is necessary to apply the appropriate settings and use your products in a secure environment. Below we have outlined a number of security measures intended to help customers use Canon products in a more secure way.
 
 

Security measures when using Canon products

 

When setting up the product

  1. Only connect products to trusted networks.
  2. It is not recommended that a product is connected directly to the internet. When connecting to the internet, use a private IP address in an environment where the internet can be accessed from a secure private network built with firewall products, wired routers or Wi-Fi routers.
  3. Change the product’s default password to a new password.
  4. Set up administrator and general users IDs and passwords if possible.
  5. Ensure that passwords and other similar settings for various functions are sufficiently difficult to guess.
  6. If the product has authentication functions, use them to confirm the end-user identity who uses the product.
  7. If the product has multi-factor authentication functions, use them to confirm the end-user identity who uses the product.
  8. If the product has network filters, use them to limit the addresses that can communicate with the product.
  9. Use any encryption functions the product may have.
  10. When possible, disable functions and ports that aren’t being used.
  11. Set the product’s security function settings as strong as possible.
  12. Be aware of physical security needs, including those related to the location of the product etc.

When operating the product

  1. When using functions that communicate via a network, ensure you are using a trusted connection destination (e.g. server) before connecting.
  2. Regularly check the Canon website to ensure you are up to date with security-related information.
  3. Use the latest firmware.
  4. If the product saves communication logs, check them regularly to find any unauthorized access.
  5. If you won’t be using the product for a long period, switch it off.
  6. Back up the data and settings stored in the product regularly.

When disposing the product

  1. When disposing the product, delete all data and set-points saved on the device.
 
 

Related information

 
Setup procedures for security measures and usage of Canon products can be found in the information below and the manuals of each product.
*For some products, the latest information is available on the manual website.
 

Useful Tips for Reducing the Risk of Unauthorized Access Manual Website
Inkjet Printer, Business Inkjet Printer PDF (806KB)
Large-Format Inkjet Printer PDF (1.06MB)
LBP and Small Office MFPs PDF (566KB) Manual
MFPs for Office and MFPs for Production Printing PDF (982KB) Manual
Network Cameras PDF (2.6MB)
Network Scanners PDF (602KB)

Report a Product Security Issue