CVE-2024-12649
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
28/01/2025
Last modified:
26/01/2026
Description
Buffer overflow in XPS data font processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw firmware v05.04 and earlier sold in Japan. Color imageCLASS MF656Cdw/Color imageCLASS MF654Cdw/Color imageCLASS MF653Cdw/Color imageCLASS MF652Cdw/Color imageCLASS LBP633Cdw/Color imageCLASS LBP632Cdw firmware v05.04 and earlier sold in US. i-SENSYS MF657Cdw/i-SENSYS MF655Cdw/i-SENSYS MF651Cdw/i-SENSYS LBP633Cdw/i-SENSYS LBP631Cdw firmware v05.04 and earlier sold in Europe.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:canon:mf455dw_firmware:*:*:*:*:*:*:*:* | 05.04 (including) | |
| cpe:2.3:h:canon:mf455dw:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:canon:mf453dw_firmware:*:*:*:*:*:*:*:* | 05.04 (including) | |
| cpe:2.3:h:canon:mf453dw:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:canon:mf452dw_firmware:*:*:*:*:*:*:*:* | 05.04 (including) | |
| cpe:2.3:h:canon:mf452dw:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:canon:mf451dw_firmware:*:*:*:*:*:*:*:* | 05.04 (including) | |
| cpe:2.3:h:canon:mf451dw:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:canon:mf465dw_firmware:*:*:*:*:*:*:*:* | 05.04 (including) | |
| cpe:2.3:h:canon:mf465dw:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:canon:mf462dw_firmware:*:*:*:*:*:*:*:* | 05.04 (including) | |
| cpe:2.3:h:canon:mf462dw:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:canon:mf656cdw_firmware:*:*:*:*:*:*:*:* | 05.04 (including) | |
| cpe:2.3:h:canon:mf656cdw:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:canon:mf654cdw_firmware:*:*:*:*:*:*:*:* | 05.04 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://canon.jp/support/support-info/250127vulnerability-response
- https://psirt.canon/advisory-information/cp2025-001/
- https://www.canon-europe.com/support/product-security/#news
- https://www.usa.canon.com/support/canon-product-advisories/service-notice-regarding-vulnerability-measure-against-buffer-overflow-for-laser-printers-and-small-office-multifunctional-printers



