PT-2024-14903 · Canon · I-Sensys C1333I Series+9

Published

2024-02-05

·

Updated

2024-02-13

·

CVE-2023-6230

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Satera LBP670C Series versions v03.07 and earlier Satera MF750C Series versions v03.07 and earlier Color imageCLASS LBP674C versions v03.07 and earlier Color imageCLASS X LBP1333C versions v03.07 and earlier Color imageCLASS MF750C Series versions v03.07 and earlier Color imageCLASS X MF1333C Series versions v03.07 and earlier i-SENSYS LBP673Cdw versions v03.07 and earlier i-SENSYS C1333P versions v03.07 and earlier i-SENSYS MF750C Series versions v03.07 and earlier i-SENSYS C1333i Series versions v03.07 and earlier
Description A buffer overflow in the Address Book password process in authentication of Mobile Device Function of Office Multifunction Printers and Laser Printers may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.
Recommendations For Satera LBP670C Series versions v03.07 and earlier, update the firmware to a version later than v03.07. For Satera MF750C Series versions v03.07 and earlier, update the firmware to a version later than v03.07. For Color imageCLASS LBP674C versions v03.07 and earlier, update the firmware to a version later than v03.07. For Color imageCLASS X LBP1333C versions v03.07 and earlier, update the firmware to a version later than v03.07. For Color imageCLASS MF750C Series versions v03.07 and earlier, update the firmware to a version later than v03.07. For Color imageCLASS X MF1333C Series versions v03.07 and earlier, update the firmware to a version later than v03.07. For i-SENSYS LBP673Cdw versions v03.07 and earlier, update the firmware to a version later than v03.07. For i-SENSYS C1333P versions v03.07 and earlier, update the firmware to a version later than v03.07. For i-SENSYS MF750C Series versions v03.07 and earlier, update the firmware to a version later than v03.07. For i-SENSYS C1333i Series versions v03.07 and earlier, update the firmware to a version later than v03.07.

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2023-6230
ZDI-24-090

Affected Products

Color Imageclass Lbp674C
Color Imageclass Mf750C Series
Color Imageclass X Lbp1333C
Color Imageclass X Mf1333C Series
Satera Lbp670C Series
Satera Mf750C Series
I-Sensys C1333P
I-Sensys C1333I Series
I-Sensys Lbp673Cdw
I-Sensys Mf750C Series