PT-2023-7444 · Canon · Canon Pixma+6
Chi Tran
·
Published
2023-05-04
·
Updated
2023-09-12
·
CVE-2023-0855
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Canon imageCLASS series versions prior to firmware Ver.11.04
Canon LBP series versions prior to firmware Ver.11.04
Canon MF series versions prior to firmware Ver.11.04
Canon i-SENSYS series versions prior to firmware Ver.11.04
Canon PIXMA series (affected versions not specified)
Canon MAXIFY series (affected versions not specified)
Canon imagePROGRAF series (affected versions not specified)
Description
The issue is related to a buffer overflow in the IPP number-up attribute process of Canon printers, which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. This can be exploited by a remote attacker.
Recommendations
For Canon imageCLASS series versions prior to firmware Ver.11.04, update to firmware Ver.11.05 or later.
For Canon LBP series versions prior to firmware Ver.11.04, update to firmware Ver.11.05 or later.
For Canon MF series versions prior to firmware Ver.11.04, update to firmware Ver.11.05 or later.
For Canon i-SENSYS series versions prior to firmware Ver.11.04, update to firmware Ver.11.05 or later.
For Canon PIXMA, MAXIFY, and imagePROGRAF series, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Stack Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Canon Lbp
Canon Maxify
Canon Mf
Canon Pixma
Canon I-Sensys
Canon Imageclass
Canon Imageprograf