CVE-2024-12649

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
28/01/2025
Last modified:
26/01/2026

Description

Buffer overflow in XPS data font processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw firmware v05.04 and earlier sold in Japan. Color imageCLASS MF656Cdw/Color imageCLASS MF654Cdw/Color imageCLASS MF653Cdw/Color imageCLASS MF652Cdw/Color imageCLASS LBP633Cdw/Color imageCLASS LBP632Cdw firmware v05.04 and earlier sold in US. i-SENSYS MF657Cdw/i-SENSYS MF655Cdw/i-SENSYS MF651Cdw/i-SENSYS LBP633Cdw/i-SENSYS LBP631Cdw firmware v05.04 and earlier sold in Europe.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:canon:mf455dw_firmware:*:*:*:*:*:*:*:* 05.04 (including)
cpe:2.3:h:canon:mf455dw:-:*:*:*:*:*:*:*
cpe:2.3:o:canon:mf453dw_firmware:*:*:*:*:*:*:*:* 05.04 (including)
cpe:2.3:h:canon:mf453dw:-:*:*:*:*:*:*:*
cpe:2.3:o:canon:mf452dw_firmware:*:*:*:*:*:*:*:* 05.04 (including)
cpe:2.3:h:canon:mf452dw:-:*:*:*:*:*:*:*
cpe:2.3:o:canon:mf451dw_firmware:*:*:*:*:*:*:*:* 05.04 (including)
cpe:2.3:h:canon:mf451dw:-:*:*:*:*:*:*:*
cpe:2.3:o:canon:mf465dw_firmware:*:*:*:*:*:*:*:* 05.04 (including)
cpe:2.3:h:canon:mf465dw:-:*:*:*:*:*:*:*
cpe:2.3:o:canon:mf462dw_firmware:*:*:*:*:*:*:*:* 05.04 (including)
cpe:2.3:h:canon:mf462dw:-:*:*:*:*:*:*:*
cpe:2.3:o:canon:mf656cdw_firmware:*:*:*:*:*:*:*:* 05.04 (including)
cpe:2.3:h:canon:mf656cdw:-:*:*:*:*:*:*:*
cpe:2.3:o:canon:mf654cdw_firmware:*:*:*:*:*:*:*:* 05.04 (including)