Arbitrary Code Execution Vulnerability in Canon imageCLASS Printers
CVE-2022-43608

8.8HIGH

Key Information:

Vendor

Canon

Vendor
CVE Published:
29 March 2023

What is CVE-2022-43608?

A vulnerability has been identified in Canon's imageCLASS MF644Cdw 10.03 printers that allows network-adjacent attackers to execute arbitrary code without requiring authentication. The flaw originates from the BJNP service’s inability to properly validate user-supplied data. This can lead to an integer overflow, which occurs prior to buffer allocation, thereby enabling an attacker to execute code with root privileges. For more details, refer to the Zero Day Initiative and Canon's advisory.

Affected Version(s)

imageCLASS MF644Cdw 10.03

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Angelboy(@scwuaptx) from DEVCORE Research Team
.