CVE-2023-6234
Buffer overflow in CPCA Color LUT Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.38%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflow in CPCA Color LUT Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.38% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- canon/mf755cdw firmware · canon/mf753cdw firmware · canon/mf751cdw firmware · canon/lbp674c firmware · canon/lbp672c firmware · canon/lbp671c firmware · canon/mf1238 ii firmware · canon/mf1333c firmware · canon/mf1643i ii firmware · canon/mf1643if ii firmware · canon/mf275dw firmware · canon/mf273dw firmware · canon/mf272dw firmware · canon/mf455dw firmware · canon/mf453dw firmware · canon/mf452dw firmware · canon/mf451dw firmware · canon/lbp122dw firmware · canon/lbp1238 ii firmware · canon/lbp1333c firmware · +9 more
- Source
- f98c90f0-e9bd-4fa7-911b-51993f3571fd
References
- https://canon.jp/support/support-info/240205vulnerability-responseVendor Advisory
- https://psirt.canon/advisory-information/cp2024-001/Vendor Advisory
- https://www.canon-europe.com/support/product-security-latest-news/Vendor Advisory
- https://www.usa.canon.com/support/canon-product-advisories/Service-Notice-Regarding-Vulnerability-Measure-Against-Buffer-Overflow-for-Laser-Printers-and-Small-Office-Multifunctional-PrintersVendor Advisory
- https://canon.jp/support/support-info/240205vulnerability-responseVendor Advisory
- https://psirt.canon/advisory-information/cp2024-001/Vendor Advisory
- https://www.canon-europe.com/support/product-security-latest-news/Vendor Advisory
- https://www.usa.canon.com/support/canon-product-advisories/Service-Notice-Regarding-Vulnerability-Measure-Against-Buffer-Overflow-for-Laser-Printers-and-Small-Office-Multifunctional-PrintersVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.