PT-2025-1926 · Canon · I-Sensys Mf651Cdw+12

Exluck

·

Published

2024-12-16

·

Updated

2026-01-26

·

CVE-2024-12649

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Color imageCLASS MF656Cdw versions v05.04 and earlier Color imageCLASS MF654Cdw versions v05.04 and earlier Color imageCLASS MF653Cdw versions v05.04 and earlier Color imageCLASS MF652Cdw versions v05.04 and earlier Color imageCLASS LBP633Cdw versions v05.04 and earlier Color imageCLASS LBP632Cdw versions v05.04 and earlier i-SENSYS MF657Cdw versions v05.04 and earlier i-SENSYS MF655Cdw versions v05.04 and earlier i-SENSYS MF651Cdw versions v05.04 and earlier i-SENSYS LBP633Cdw versions v05.04 and earlier i-SENSYS LBP631Cdw versions v05.04 and earlier Satera MF656Cdw versions v05.04 and earlier Satera MF654Cdw versions v05.04 and earlier
Description A buffer overflow issue in XPS data font processing may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.
Recommendations For Color imageCLASS MF656Cdw version v05.04 and earlier, update the firmware to a version later than v05.04. For Color imageCLASS MF654Cdw version v05.04 and earlier, update the firmware to a version later than v05.04. For Color imageCLASS MF653Cdw version v05.04 and earlier, update the firmware to a version later than v05.04. For Color imageCLASS MF652Cdw version v05.04 and earlier, update the firmware to a version later than v05.04. For Color imageCLASS LBP633Cdw version v05.04 and earlier, update the firmware to a version later than v05.04. For Color imageCLASS LBP632Cdw version v05.04 and earlier, update the firmware to a version later than v05.04. For i-SENSYS MF657Cdw version v05.04 and earlier, update the firmware to a version later than v05.04. For i-SENSYS MF655Cdw version v05.04 and earlier, update the firmware to a version later than v05.04. For i-SENSYS MF651Cdw version v05.04 and earlier, update the firmware to a version later than v05.04. For i-SENSYS LBP633Cdw version v05.04 and earlier, update the firmware to a version later than v05.04. For i-SENSYS LBP631Cdw version v05.04 and earlier, update the firmware to a version later than v05.04. For Satera MF656Cdw version v05.04 and earlier, update the firmware to a version later than v05.04. For Satera MF654Cdw version v05.04 and earlier, update the firmware to a version later than v05.04.

Fix

RCE

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2025-04001
CVE-2024-12649
ZDI-25-075

Affected Products

Color Imageclass Lbp632Cdw
Color Imageclass Lbp633Cdw
Color Imageclass Mf652Cdw
Color Imageclass Mf653Cdw
Color Imageclass Mf654Cdw
Color Imageclass Mf656Cdw
Satera Mf654Cdw
Satera Mf656Cdw
I-Sensys Lbp631Cdw
I-Sensys Lbp633Cdw
I-Sensys Mf651Cdw
I-Sensys Mf655Cdw
I-Sensys Mf657Cdw