SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-0244

Buffer overflow in CPCA PCFAX number process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF750C Series…

CRITICAL 9.8EPSS 1.38%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.38%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Buffer overflow in CPCA PCFAX number process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS MF750C Series/Color imageCLASS X MF1333C firmware v03.07 and earlier sold in US. i-SENSYS MF754Cdw/C1333iF firmware v03.07 and earlier sold in Europe.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.38% probability · 71th percentile
CISA KEV
Not listed
Weakness
CWE-787
Affected
canon/i-sensys mf754cdw firmware · canon/i-sensys x c1333if firmware · canon/mf755cdw firmware · canon/mf753cdw firmware · canon/mf751cdw firmware · canon/mf1333c firmware · canon/lbp1333c firmware
Source
f98c90f0-e9bd-4fa7-911b-51993f3571fd

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.