CVE-2023-0855
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
11/05/2023
Last modified:
07/11/2023
Description
Buffer overflow in IPP number-up attribute process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier sold in US. i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF, C1127i firmware Ver.11.04 and earlier sold in Europe.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:canon:mf642cdw_firmware:*:*:*:*:*:*:*:* | 11.04 (including) | |
| cpe:2.3:h:canon:mf642cdw:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:canon:mf644cdw_firmware:*:*:*:*:*:*:*:* | 11.04 (including) | |
| cpe:2.3:h:canon:mf644cdw:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:canon:mf741cdw_firmware:*:*:*:*:*:*:*:* | 11.04 (including) | |
| cpe:2.3:h:canon:mf741cdw:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:canon:mf743cdw_firmware:*:*:*:*:*:*:*:* | 11.04 (including) | |
| cpe:2.3:h:canon:mf743cdw:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:canon:mf745cdw_firmware:*:*:*:*:*:*:*:* | 11.04 (including) | |
| cpe:2.3:h:canon:mf745cdw:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:canon:lbp621c_firmware:*:*:*:*:*:*:*:* | 11.04 (including) | |
| cpe:2.3:h:canon:lbp621c:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:canon:lbp622c_firmware:*:*:*:*:*:*:*:* | 11.04 (including) | |
| cpe:2.3:h:canon:lbp622c:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:canon:lbp661c_firmware:*:*:*:*:*:*:*:* | 11.04 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://canon.jp/support/support-info/230414vulnerability-response
- https://psirt.canon/advisory-information/cp2023-001/
- https://www.canon-europe.com/support/product-security-latest-news/
- https://www.usa.canon.com/support/canon-product-advisories/Service-Notice-Vulnerabilities-Remediation-Against-Buffer-Overflow



