Arbitrary Code Execution Vulnerability in Canon imageCLASS Printers
CVE-2022-43608
8.8HIGH
What is CVE-2022-43608?
A vulnerability has been identified in Canon's imageCLASS MF644Cdw 10.03 printers that allows network-adjacent attackers to execute arbitrary code without requiring authentication. The flaw originates from the BJNP service’s inability to properly validate user-supplied data. This can lead to an integer overflow, which occurs prior to buffer allocation, thereby enabling an attacker to execute code with root privileges. For more details, refer to the Zero Day Initiative and Canon's advisory.
Affected Version(s)
imageCLASS MF644Cdw 10.03
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Angelboy(@scwuaptx) from DEVCORE Research Team