PT-2024-1699 · Canon · Canon Imageclass Mf750C Series+4

Connor Ford

·

Published

2024-02-05

·

Updated

2024-02-13

·

CVE-2024-0244

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Canon imageCLASS MF753Cdw version 03.07 and earlier Canon imageCLASS MF750C Series version 03.07 and earlier Color imageCLASS X MF1333C version 03.07 and earlier i-SENSYS MF754Cdw version 03.07 and earlier i-SENSYS MF754Cdw/C1333iF version 03.07 and earlier Satera MF750C Series version 03.07 and earlier
Description The issue is related to a buffer overflow in the CPCA PCFAX number process of Office Multifunction Printers and Laser Printers, which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. The exploitation of this issue can be done remotely without requiring authentication.
Recommendations For Canon imageCLASS MF753Cdw version 03.07 and earlier, update the firmware to a version later than 03.07. For Canon imageCLASS MF750C Series version 03.07 and earlier, update the firmware to a version later than 03.07. For Color imageCLASS X MF1333C version 03.07 and earlier, update the firmware to a version later than 03.07. For i-SENSYS MF754Cdw version 03.07 and earlier, update the firmware to a version later than 03.07. For i-SENSYS MF754Cdw/C1333iF version 03.07 and earlier, update the firmware to a version later than 03.07. For Satera MF750C Series version 03.07 and earlier, update the firmware to a version later than 03.07.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-01387
CVE-2024-0244
ZDI-24-095

Affected Products

Canon Imageclass Mf750C Series
Canon Imageclass Mf753Cdw
Color Imageclass X Mf1333C
I-Sensys Mf754Cdw
I-Sensys Mf754Cdw/C1333If