PT-2023-7449 · Canon · I-Sensys C1127I+15
Published
2023-05-04
·
Updated
2023-09-12
·
CVE-2023-0854
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Canon imageCLASS series versions prior to firmware Ver.11.04
Canon imageCLASS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier
Color imageCLASS LBP660C Series/LBP620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier
i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF, C1127i firmware Ver.11.04 and earlier
Description
The issue is related to a buffer overflow in the NetBIOS QNAME registering and communication process of Canon printers, which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. This is also associated with the
cmNetBiosParseName function.Recommendations
For Canon imageCLASS series versions prior to firmware Ver.11.04, update the firmware to a version later than Ver.11.04.
For Canon imageCLASS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, update the firmware to a version later than Ver.11.04.
For Color imageCLASS LBP660C Series/LBP620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C, update the firmware to a version later than Ver.11.04.
For i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF, C1127i, update the firmware to a version later than Ver.11.04.
As a temporary workaround, consider restricting access to the
cmNetBiosParseName function until a patch is available.Fix
Memory Corruption
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Canon Imageclass Lbp620C Series
Canon Imageclass Lbp660C Series
Canon Imageclass Mf640C Series
Canon Imageclass Mf740C Series
Canon Imageclass Series
Color Imageclass Lbp620C Series
Color Imageclass Lbp660C Series
Color Imageclass Mf640C Series
Color Imageclass Mf740C Series
Color Imageclass X Lbp1127C
Color Imageclass X Mf1127C
I-Sensys C1127I
I-Sensys Lbp620C Series
I-Sensys Lbp660C Series
I-Sensys Mf640C Series
I-Sensys Mf740C Series