SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-6234

Buffer overflow in CPCA Color LUT Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:…

CRITICAL 9.8EPSS 1.38%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.38%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Buffer overflow in CPCA Color LUT Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.38% probability · 71th percentile
CISA KEV
Not listed
Weakness
CWE-787
Affected
canon/mf755cdw firmware · canon/mf753cdw firmware · canon/mf751cdw firmware · canon/lbp674c firmware · canon/lbp672c firmware · canon/lbp671c firmware · canon/mf1238 ii firmware · canon/mf1333c firmware · canon/mf1643i ii firmware · canon/mf1643if ii firmware · canon/mf275dw firmware · canon/mf273dw firmware · canon/mf272dw firmware · canon/mf455dw firmware · canon/mf453dw firmware · canon/mf452dw firmware · canon/mf451dw firmware · canon/lbp122dw firmware · canon/lbp1238 ii firmware · canon/lbp1333c firmware · +9 more
Source
f98c90f0-e9bd-4fa7-911b-51993f3571fd

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.