PT-2023-6482 · Canon · Canon Imageclass Series+1

Published

2023-04-14

·

Updated

2023-05-20

·

CVE-2023-0856

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Canon imageCLASS series versions prior to firmware Ver.11.04 Canon Office / Small Office Multifunction Printers and Laser Printers versions prior to firmware Ver.11.04
Description The issue is related to a buffer overflow in the IPP sides attribute process, which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. This is a result of a vulnerability in the implementation of the Internet Printing Protocol (IPP) in the firmware of Canon printers.
Recommendations For Canon imageCLASS series with firmware Ver.11.04 and earlier, update the firmware to a version later than Ver.11.04. For Canon Office / Small Office Multifunction Printers and Laser Printers with firmware Ver.11.04 and earlier, update the firmware to a version later than Ver.11.04. As a temporary workaround, consider restricting access to the IPP protocol until a patch is available.

Fix

Stack Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2023-07216
CVE-2023-0856
ZDI-23-556

Affected Products

Canon Office / Small Office Multifunction Printers/Laser Printers
Canon Imageclass Series