CVE-2024-12647
Buffer overflow in CPCA font download processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflow in CPCA font download processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw firmware v05.04 and earlier sold in Japan. Color imageCLASS MF656Cdw/Color imageCLASS MF654Cdw/Color imageCLASS MF653Cdw/Color imageCLASS MF652Cdw/Color imageCLASS LBP633Cdw/Color imageCLASS LBP632Cdw firmware v05.04 and earlier sold in US. i-SENSYS MF657Cdw/i-SENSYS MF655Cdw/i-SENSYS MF651Cdw/i-SENSYS LBP633Cdw/i-SENSYS LBP631Cdw firmware v05.04 and earlier sold in Europe.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.20% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- canon/mf455dw firmware · canon/mf453dw firmware · canon/mf452dw firmware · canon/mf451dw firmware · canon/mf465dw firmware · canon/mf462dw firmware · canon/mf656cdw firmware · canon/mf654cdw firmware · canon/mf653cdw firmware · canon/mf652cw firmware · canon/mf1238 ii firmware · canon/mf1440 firmware · canon/mf1643if ii firmware · canon/mf1643i ii firmware · canon/lbp237dw firmware · canon/lbp236dw firmware · canon/lbp247dw firmware · canon/lbp246dw firmware · canon/lbp633cdw firmware · canon/lbp632cdw firmware · +2 more
- Source
- f98c90f0-e9bd-4fa7-911b-51993f3571fd
References
- https://canon.jp/support/support-info/250127vulnerability-responseVendor Advisory
- https://psirt.canon/advisory-information/cp2025-001/Vendor Advisory
- https://www.canon-europe.com/support/product-security/#newsVendor Advisory
- https://www.usa.canon.com/support/canon-product-advisories/service-notice-regarding-vulnerability-measure-against-buffer-overflow-for-laser-printers-and-small-office-multifunctional-printersVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.