Buffer Overflow Vulnerability in Canon Small Office Multifunction Printers and Laser Printers
CVE-2024-12649
9.8CRITICAL
Key Information:
- Vendor
- Canon Inc.
- Status
- Satera Mf656cdw
- Satera Mf654cdw
- Color Imageclass Mf656cdw
- Color Imageclass Mf654cdw
- Vendor
- CVE Published:
- 28 January 2025
Summary
A vulnerability exists in the XPS data font processing of certain Canon Small Office Multifunction Printers and Laser Printers, allowing an attacker on the same network segment to exploit a buffer overflow. This exploitation could lead to the printer becoming unresponsive or potentially allow for the execution of arbitrary code. Various models across different regions, including Japan, the US, and Europe, are affected if they are running firmware v05.04 or earlier.
Affected Version(s)
Color imageCLASS LBP632Cdw 05.04 and earlier
Color imageCLASS LBP633Cdw 05.04 and earlier
Color imageCLASS MF652Cdw 05.04 and earlier
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved