Arbitrary Code Execution Vulnerability in Canon ImageCLASS Printers
CVE-2022-24674
What is CVE-2022-24674?
This vulnerability affects the Canon imageCLASS MF644Cdw printer model, allowing network-adjacent attackers to execute arbitrary code without requiring any form of authentication. The vulnerability is found within the privet API, which lacks proper validation of user-supplied data lengths. This flaw enables malicious actors to exploit the fixed-length stack-based buffer, executing code with root privileges, thereby compromising the device and potentially affecting the network it operates on. For more information, refer to the advisory by the Zero Day Initiative and Canon's official support page.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
imageCLASS MF644Cdw 10.02
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
