PT-2023-7446 · Canon · Canon Satera Mf640C Series+15

Le Tran Hai Tung

+1

·

Published

2023-05-04

·

Updated

2023-09-12

·

CVE-2023-0851

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Canon imageCLASS series versions prior to firmware Ver.11.04 Canon imageCLASS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series versions prior to firmware Ver.11.04 Canon i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series versions prior to firmware Ver.11.04 Canon Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series versions prior to firmware Ver.11.04 Canon PIXMA, MAXIFY, and imagePROGRAF versions (affected versions not specified)
Description The issue is related to a buffer overflow in the CPCA Resource Download process of Canon printers, which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. The vulnerability is also associated with the cmNetBiosParseName function and the resourceStart2 and setResource functions in the CADM module.
Recommendations For Canon imageCLASS series versions prior to firmware Ver.11.04: Update to firmware Ver.11.05 or later. For Canon imageCLASS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series versions prior to firmware Ver.11.04: Update to firmware Ver.11.05 or later. For Canon i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series versions prior to firmware Ver.11.04: Update to firmware Ver.11.05 or later. For Canon Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series versions prior to firmware Ver.11.04: Update to firmware Ver.11.05 or later. For Canon PIXMA, MAXIFY, and imagePROGRAF versions: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Heap Based Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2023-08485
CVE-2023-0851
ZDI-23-549
ZDI-23-550
ZDI-23-551

Affected Products

Canon Maxify
Canon Pixma
Canon Satera Lbp620C Series
Canon Satera Lbp660C Series
Canon Satera Mf640C Series
Canon Satera Mf740C Series
Canon I-Sensys Lbp620C Series
Canon I-Sensys Lbp660C Series
Canon I-Sensys Mf640C Series
Canon I-Sensys Mf740C Series
Canon Imageclass
Canon Imageclass Lbp620C Series
Canon Imageclass Lbp660C Series
Canon Imageclass Mf640C Series
Canon Imageclass Mf740C Series
Canon Imageprograf