Search

Find a vulnerability

Search criteria

    7 vulnerabilities by canon

    CVE-2024-2184 (GCVE-0-2024-2184)

    Vulnerability from cvelistv5 – Published: 2024-03-11 00:26 – Updated: 2024-08-28 20:24
    VLAI
    Summary
    Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF740C Series/Satera MF640C Series/Satera LBP660C Series/Satera LBP620C Series firmware v12.07 and earlier, and Satera MF750C Series/Satera LBP670C Series firmware v03.09 and earlier sold in Japan.Color imageCLASS MF740C Series/Color imageCLASS MF640C Series/Color imageCLASS X MF1127C/Color imageCLASS LBP664Cdw/Color imageCLASS LBP622Cdw/Color imageCLASS X LBP1127C firmware v12.07 and earlier, and Color imageCLASS MF750C Series/Color imageCLASS X MF1333C/Color imageCLASS LBP674Cdw/Color imageCLASS X LBP1333C firmware v03.09 and earlier sold in US.i-SENSYS MF740C Series/i-SENSYS MF640C Series/C1127i Series/i-SENSYS LBP660C Series/i-SENSYS LBP620C Series/C1127P firmware v12.07 and earlier, and i-SENSYS MF750C Series/C1333i Series/i-SENSYS LBP673Cdw/C1333P firmware v03.09 and earlier sold in Europe.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-11 15:11 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    Canon Inc. Color imageCLASS MF740C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS MF640C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. i-SENSYS MF740C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. i-SENSYS MF640C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Satera MF740C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Satera MF640C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS X MF1127C Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. C1127i Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS LBP664Cdw Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS LBP622Cdw Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. i-SENSYS LBP660C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. i-SENSYS LBP620C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Satera LBP660C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Satera LBP620C Series Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS X LBP1127C Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. C1127P Affected: v12.07 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS MF750C Series Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. i-SENSYS MF750C Series Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. Satera MF750C Series Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS X MF1333C Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. C1333i Series Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS LBP674Cdw Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. i-SENSYS LBP673Cdw Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. Satera LBP670C Series Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS X LBP1333C Affected: v03.09 and earlier
    Create a notification for this product.
    Canon Inc. C1333P Affected: v03.09 and earlier
    Create a notification for this product.
    canon color_imageclass_mf740c_series Affected: 0 , ≤ 12..07 (custom)
        cpe:2.3:h:canon:color_imageclass_mf740c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_mf640c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:color_imageclass_mf640c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon i-sensys_mf740c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:i-sensys_mf740c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon i-sensys_mf640c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:i-sensys_mf640c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon satera_mf740c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:satera_mf740c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_x_mf1127c Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:color_imageclass_x_mf1127c:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_lbp664cdw Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:color_imageclass_lbp664cdw:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon c1127i_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:c1127i_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_lbp622cdw Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:color_imageclass_lbp622cdw:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon i-sensys_lbp660c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:i-sensys_lbp660c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon i-sensys_lbp620c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:i-sensys_lbp620c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon i-sensys_mf750c_series Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:i-sensys_mf750c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_x_lbp1333c Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:color_imageclass_x_lbp1333c:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon i-sensys_lbp673cdw Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:i-sensys_lbp673cdw:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon satera_lbp670c_series Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:satera_lbp670c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon c1333p Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:c1333p:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon satera_mf640c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:satera_mf640c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon satera_lbp620c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:satera_lbp620c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon satera_lbp660c_series Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:satera_lbp660c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_x_lbp1127c Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:color_imageclass_x_lbp1127c:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_mf750c_series Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:color_imageclass_mf750c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon c1127p Affected: 0 , ≤ 12.07 (custom)
        cpe:2.3:h:canon:c1127p:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon satera_mf750c_series Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:satera_mf750c_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_x_mf1333c Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:color_imageclass_x_mf1333c:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon c1333i_series Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:c1333i_series:*:*:*:*:*:*:*:*
    Create a notification for this product.
    canon color_imageclass_lbp674cdw Affected: 0 , ≤ 03.09 (custom)
        cpe:2.3:h:canon:color_imageclass_lbp674cdw:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T19:03:39.266Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://psirt.canon/advisory-information/cp2024-002/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_mf740c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_mf740c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12..07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_mf640c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_mf640c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:i-sensys_mf740c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "i-sensys_mf740c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:i-sensys_mf640c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "i-sensys_mf640c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:satera_mf740c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "satera_mf740c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_x_mf1127c:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_x_mf1127c",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_lbp664cdw:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_lbp664cdw",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:c1127i_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "c1127i_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_lbp622cdw:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_lbp622cdw",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:i-sensys_lbp660c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "i-sensys_lbp660c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:i-sensys_lbp620c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "i-sensys_lbp620c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:i-sensys_mf750c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "i-sensys_mf750c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_x_lbp1333c:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_x_lbp1333c",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:i-sensys_lbp673cdw:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "i-sensys_lbp673cdw",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:satera_lbp670c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "satera_lbp670c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:c1333p:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "c1333p",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:satera_mf640c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "satera_mf640c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:satera_lbp620c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "satera_lbp620c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:satera_lbp660c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "satera_lbp660c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_x_lbp1127c:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_x_lbp1127c",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_mf750c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_mf750c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:c1127p:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "c1127p",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "12.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:satera_mf750c_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "satera_mf750c_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_x_mf1333c:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_x_mf1333c",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:c1333i_series:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "c1333i_series",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:color_imageclass_lbp674cdw:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "color_imageclass_lbp674cdw",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "03.09",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-2184",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-11T15:11:33.695685Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-28T20:24:54.597Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Color imageCLASS MF740C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS MF640C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "i-SENSYS MF740C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "i-SENSYS MF640C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Satera MF740C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Satera MF640C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS X MF1127C",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "C1127i Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS LBP664Cdw",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS LBP622Cdw",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "i-SENSYS LBP660C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "i-SENSYS LBP620C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Satera LBP660C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Satera LBP620C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS X LBP1127C",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "C1127P",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v12.07 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS MF750C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "i-SENSYS MF750C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "Satera MF750C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS X MF1333C",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "C1333i Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS LBP674Cdw",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "i-SENSYS LBP673Cdw",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "Satera LBP670C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "Color imageCLASS X LBP1333C",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            },
            {
              "product": "C1333P",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "v03.09 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eBuffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF740C Series/Satera MF640C Series/Satera LBP660C Series/Satera LBP620C Series firmware v12.07 and earlier, and Satera MF750C Series/Satera LBP670C Series firmware v03.09 and earlier sold in Japan.Color imageCLASS MF740C Series/Color imageCLASS MF640C Series/Color imageCLASS X MF1127C/Color imageCLASS LBP664Cdw/Color imageCLASS LBP622Cdw/Color imageCLASS X LBP1127C firmware v12.07 and earlier, and Color imageCLASS MF750C Series/Color imageCLASS X MF1333C/Color imageCLASS LBP674Cdw/Color imageCLASS X LBP1333C firmware v03.09 and earlier sold in US.i-SENSYS MF740C Series/i-SENSYS MF640C Series/C1127i Series/i-SENSYS LBP660C Series/i-SENSYS LBP620C Series/C1127P firmware v12.07 and earlier, and i-SENSYS MF750C Series/C1333i Series/i-SENSYS LBP673Cdw/C1333P firmware v03.09 and earlier sold in Europe.\u003c/p\u003e"
                }
              ],
              "value": "Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF740C Series/Satera MF640C Series/Satera LBP660C Series/Satera LBP620C Series firmware v12.07 and earlier, and Satera MF750C Series/Satera LBP670C Series firmware v03.09 and earlier sold in Japan.Color imageCLASS MF740C Series/Color imageCLASS MF640C Series/Color imageCLASS X MF1127C/Color imageCLASS LBP664Cdw/Color imageCLASS LBP622Cdw/Color imageCLASS X LBP1127C firmware v12.07 and earlier, and Color imageCLASS MF750C Series/Color imageCLASS X MF1333C/Color imageCLASS LBP674Cdw/Color imageCLASS X LBP1333C firmware v03.09 and earlier sold in US.i-SENSYS MF740C Series/i-SENSYS MF640C Series/C1127i Series/i-SENSYS LBP660C Series/i-SENSYS LBP620C Series/C1127P firmware v12.07 and earlier, and i-SENSYS MF750C Series/C1333i Series/i-SENSYS LBP673Cdw/C1333P firmware v03.09 and earlier sold in Europe.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787: Out-of-bounds Write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-11T00:26:02.346Z",
            "orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
            "shortName": "Canon"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://psirt.canon/advisory-information/cp2024-002/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
        "assignerShortName": "Canon",
        "cveId": "CVE-2024-2184",
        "datePublished": "2024-03-11T00:26:02.346Z",
        "dateReserved": "2024-03-05T00:44:00.599Z",
        "dateUpdated": "2024-08-28T20:24:54.597Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-6234 (GCVE-0-2023-6234)

    Vulnerability from cvelistv5 – Published: 2024-02-06 00:23 – Updated: 2024-08-02 08:21
    VLAI
    Summary
    Buffer overflow in CPCA Color LUT Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-04 14:15 UTC
    CWE
    Impacted products
    Vendor Product Version
    Canon Inc. Satera LBP670C Series Affected: 03.07 and earlier
    Create a notification for this product.
    Canon Inc. Satera MF750C Series Affected: 03.07 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS LBP674C Affected: 03.07 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS X LBP1333C Affected: 03.07 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS MF750C Series Affected: 03.07 and earlier
    Create a notification for this product.
    Canon Inc. Color imageCLASS X MF1333C Series Affected: 03.07 and earlier
    Create a notification for this product.
    Canon Inc. i-SENSYS LBP673Cdw Affected: 03.07 and earlier
    Create a notification for this product.
    Canon Inc. C1333P Affected: 03.07 and earlier
    Create a notification for this product.
    Canon Inc. i-SENSYS MF750C Series Affected: 03.07 and earlier
    Create a notification for this product.
    Canon Inc. C1333i Series Affected: 03.07 and earlier
    Create a notification for this product.
    canon lbp674c Affected: 0 , ≤ 3.07 (custom)
        cpe:2.3:h:canon:lbp674c:-:*:*:*:*:*:*:*
    Create a notification for this product.
    canon lbp1333c Affected: 0 , ≤ 3.07 (custom)
        cpe:2.3:h:canon:lbp1333c:-:*:*:*:*:*:*:*
    Create a notification for this product.
    canon i-sensys_x_c1333p Affected: 0 , ≤ 3.07 (custom)
        cpe:2.3:h:canon:i-sensys_x_c1333p:-:*:*:*:*:*:*:*
    Create a notification for this product.
    canon i-sensys_lbp673cdw Affected: 0 , ≤ 3.07 (custom)
        cpe:2.3:h:canon:i-sensys_lbp673cdw:-:*:*:*:*:*:*:*
    Create a notification for this product.
    canon mf1333c Affected: 0 , ≤ 3.07 (custom)
        cpe:2.3:h:canon:mf1333c:-:*:*:*:*:*:*:*
    Create a notification for this product.
    canon mf750c Affected: 0 , ≤ 3.07 (custom)
        cpe:2.3:h:canon:mf750c:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:canon:lbp674c:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "lbp674c",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "3.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:lbp1333c:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "lbp1333c",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "3.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:i-sensys_x_c1333p:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "i-sensys_x_c1333p",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "3.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:i-sensys_lbp673cdw:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "i-sensys_lbp673cdw",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "3.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:mf1333c:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mf1333c",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "3.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:canon:mf750c:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mf750c",
                "vendor": "canon",
                "versions": [
                  {
                    "lessThanOrEqual": "3.07",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-6234",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-04T14:15:16.906621Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-04T17:16:57.552Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T08:21:17.875Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://psirt.canon/advisory-information/cp2024-001/"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://canon.jp/support/support-info/240205vulnerability-response"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://www.usa.canon.com/support/canon-product-advisories/Service-Notice-Regarding-Vulnerability-Measure-Against-Buffer-Overflow-for-Laser-Printers-and-Small-Office-Multifunctional-Printers"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://www.canon-europe.com/support/product-security-latest-news/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Satera LBP670C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "03.07 and earlier"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Satera MF750C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "03.07 and earlier"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Color imageCLASS LBP674C",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "03.07 and earlier"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Color imageCLASS X LBP1333C",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "03.07 and earlier"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Color imageCLASS MF750C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "03.07 and earlier"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Color imageCLASS X MF1333C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "03.07 and earlier"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "i-SENSYS LBP673Cdw",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "03.07 and earlier"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "C1333P",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "03.07 and earlier"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "i-SENSYS MF750C Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "03.07 and earlier"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "C1333i Series",
              "vendor": "Canon Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "03.07 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eBuffer overflow in CPCA Color LUT Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.\u003c/p\u003e"
                }
              ],
              "value": "Buffer overflow in CPCA Color LUT Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787: Out-of-bounds Write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-02-06T00:23:28.727Z",
            "orgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
            "shortName": "Canon"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://psirt.canon/advisory-information/cp2024-001/"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://canon.jp/support/support-info/240205vulnerability-response"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.usa.canon.com/support/canon-product-advisories/Service-Notice-Regarding-Vulnerability-Measure-Against-Buffer-Overflow-for-Laser-Printers-and-Small-Office-Multifunctional-Printers"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.canon-europe.com/support/product-security-latest-news/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
        "assignerShortName": "Canon",
        "cveId": "CVE-2023-6234",
        "datePublished": "2024-02-06T00:23:28.727Z",
        "dateReserved": "2023-11-21T06:05:11.045Z",
        "dateUpdated": "2024-08-02T08:21:17.875Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-43608 (GCVE-0-2022-43608)

    Vulnerability from cvelistv5 – Published: 2023-03-29 00:00 – Updated: 2025-02-14 20:24
    VLAI
    Summary
    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.03 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the BJNP service. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-16032.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-14 20:24 UTC
    CWE
    • CWE-190 - Integer Overflow or Wraparound
    Assigner
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T13:32:59.829Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1666/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.psirt.canon/advisory-information/cve-2022-43608_20221125"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-43608",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-14T20:24:05.481052Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-14T20:24:10.588Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "imageCLASS MF644Cdw",
              "vendor": "Canon",
              "versions": [
                {
                  "status": "affected",
                  "version": "10.03"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Angelboy(@scwuaptx) from DEVCORE Research Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.03 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the BJNP service. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-16032."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "LOW",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-190",
                  "description": "CWE-190: Integer Overflow or Wraparound",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-03-29T00:00:00.000Z",
            "orgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
            "shortName": "zdi"
          },
          "references": [
            {
              "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1666/"
            },
            {
              "url": "https://www.psirt.canon/advisory-information/cve-2022-43608_20221125"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
        "assignerShortName": "zdi",
        "cveId": "CVE-2022-43608",
        "datePublished": "2023-03-29T00:00:00.000Z",
        "dateReserved": "2022-10-21T00:00:00.000Z",
        "dateUpdated": "2025-02-14T20:24:10.588Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-24673 (GCVE-0-2022-24673)

    Vulnerability from cvelistv5 – Published: 2023-03-28 00:00 – Updated: 2025-02-19 15:39
    VLAI
    Summary
    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the SLP protocol. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15845.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-19 15:39 UTC
    CWE
    • CWE-121 - Stack-based Buffer Overflow
    Assigner
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T04:20:49.148Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-515/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.usa.canon.com/support/canon-product-advisories/canon-laser-printer-inkjet-printer-and-small-office-multifunctional-printer-measure-against-buffer-overflow"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-24673",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-19T15:39:46.782842Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-19T15:39:58.261Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "imageCLASS MF644Cdw",
              "vendor": "Canon",
              "versions": [
                {
                  "status": "affected",
                  "version": "10.02"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Angelboy (@scwuaptx) from DEVCORE Research Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This vulnerability allows remote attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the SLP protocol. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15845."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "LOW",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121: Stack-based Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-03-28T00:00:00.000Z",
            "orgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
            "shortName": "zdi"
          },
          "references": [
            {
              "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-515/"
            },
            {
              "url": "https://www.usa.canon.com/support/canon-product-advisories/canon-laser-printer-inkjet-printer-and-small-office-multifunctional-printer-measure-against-buffer-overflow"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
        "assignerShortName": "zdi",
        "cveId": "CVE-2022-24673",
        "datePublished": "2023-03-28T00:00:00.000Z",
        "dateReserved": "2022-02-08T00:00:00.000Z",
        "dateUpdated": "2025-02-19T15:39:58.261Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-24672 (GCVE-0-2022-24672)

    Vulnerability from cvelistv5 – Published: 2023-03-28 00:00 – Updated: 2025-02-19 15:41
    VLAI
    Summary
    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CADM service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-15802.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-19 15:40 UTC
    CWE
    • CWE-122 - Heap-based Buffer Overflow
    Assigner
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T04:20:49.127Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-514/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.usa.canon.com/support/canon-product-advisories/canon-laser-printer-inkjet-printer-and-small-office-multifunctio"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-24672",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-19T15:40:11.420775Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-19T15:41:43.674Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "imageCLASS MF644Cdw",
              "vendor": "Canon",
              "versions": [
                {
                  "status": "affected",
                  "version": "10.02"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Mehdi Talbi (@abu_y0ussef), Remi Jullian (@netsecurity1), Thomas Jeunet (@cleptho), from @Synacktiv"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CADM service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-15802."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "LOW",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-122",
                  "description": "CWE-122: Heap-based Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-03-28T00:00:00.000Z",
            "orgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
            "shortName": "zdi"
          },
          "references": [
            {
              "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-514/"
            },
            {
              "url": "https://www.usa.canon.com/support/canon-product-advisories/canon-laser-printer-inkjet-printer-and-small-office-multifunctio"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
        "assignerShortName": "zdi",
        "cveId": "CVE-2022-24672",
        "datePublished": "2023-03-28T00:00:00.000Z",
        "dateReserved": "2022-02-08T00:00:00.000Z",
        "dateUpdated": "2025-02-19T15:41:43.674Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-24674 (GCVE-0-2022-24674)

    Vulnerability from cvelistv5 – Published: 2023-03-28 00:00 – Updated: 2025-02-19 15:37
    VLAI
    Summary
    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the privet API. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15834.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-19 15:37 UTC
    CWE
    • CWE-121 - Stack-based Buffer Overflow
    Assigner
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T04:20:49.145Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-516/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/canon-laser-printer-and-small-office-multifunctional-printer-measure-against-buffer-overflow/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-24674",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-19T15:37:17.104491Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-19T15:37:21.554Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "imageCLASS MF644Cdw",
              "vendor": "Canon",
              "versions": [
                {
                  "status": "affected",
                  "version": "10.02"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Nicolas Devillers ( @nikaiw ), Jean-Romain Garnier and Raphael Rigo ( @_trou_ )"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the privet API. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15834."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "LOW",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121: Stack-based Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-03-28T00:00:00.000Z",
            "orgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
            "shortName": "zdi"
          },
          "references": [
            {
              "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-516/"
            },
            {
              "url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/canon-laser-printer-and-small-office-multifunctional-printer-measure-against-buffer-overflow/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
        "assignerShortName": "zdi",
        "cveId": "CVE-2022-24674",
        "datePublished": "2023-03-28T00:00:00.000Z",
        "dateReserved": "2022-02-08T00:00:00.000Z",
        "dateUpdated": "2025-02-19T15:37:21.554Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-20877 (GCVE-0-2021-20877)

    Vulnerability from cvelistv5 – Published: 2022-02-08 10:30 – Updated: 2024-08-03 17:53
    VLAI
    Summary
    Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series (MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series (LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS (LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER (2206IF, 2204N, and 2204F) sold in Europe) allows remote attackers to inject an arbitrary script via unspecified vectors.
    Severity
    No CVSS data available.
    CWE
    • Cross-site scripting
    Impacted products
    Vendor Product Version
    Canon Canon laser printers and small office multifunctional printers Affected: LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series(MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series(LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS(LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER(2206IF, 2204N, and 2204F) sold in Europe
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T17:53:23.123Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://cweb.canon.jp/e-support/info/211221xss.html"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/Service-Notice-Canon-Laser-Printer-and-Small-Office-Multifunctional-Printer-related-to-cross-site-scripting"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.canon-europe.com/support/product-security-latest-news/"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/jp/JVN64806328/index.html"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jvn.jp/jp/JVN64806328/index.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Canon laser printers and small office multifunctional printers",
              "vendor": "Canon",
              "versions": [
                {
                  "status": "affected",
                  "version": "LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series(MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series(LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS(LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER(2206IF, 2204N, and 2204F) sold in Europe"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series (MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series (LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS (LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER (2206IF, 2204N, and 2204F) sold in Europe) allows remote attackers to inject an arbitrary script via unspecified vectors."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Cross-site scripting",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-02-08T10:30:31.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://cweb.canon.jp/e-support/info/211221xss.html"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/Service-Notice-Canon-Laser-Printer-and-Small-Office-Multifunctional-Printer-related-to-cross-site-scripting"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.canon-europe.com/support/product-security-latest-news/"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jvn.jp/en/jp/JVN64806328/index.html"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jvn.jp/jp/JVN64806328/index.html"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vultures@jpcert.or.jp",
              "ID": "CVE-2021-20877",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Canon laser printers and small office multifunctional printers",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series(MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series(LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS(LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER(2206IF, 2204N, and 2204F) sold in Europe"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Canon"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series (MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series (LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS (LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER (2206IF, 2204N, and 2204F) sold in Europe) allows remote attackers to inject an arbitrary script via unspecified vectors."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Cross-site scripting"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://cweb.canon.jp/e-support/info/211221xss.html",
                  "refsource": "MISC",
                  "url": "https://cweb.canon.jp/e-support/info/211221xss.html"
                },
                {
                  "name": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/Service-Notice-Canon-Laser-Printer-and-Small-Office-Multifunctional-Printer-related-to-cross-site-scripting",
                  "refsource": "MISC",
                  "url": "https://www.usa.canon.com/internet/portal/us/home/support/product-advisories/detail/Service-Notice-Canon-Laser-Printer-and-Small-Office-Multifunctional-Printer-related-to-cross-site-scripting"
                },
                {
                  "name": "https://www.canon-europe.com/support/product-security-latest-news/",
                  "refsource": "MISC",
                  "url": "https://www.canon-europe.com/support/product-security-latest-news/"
                },
                {
                  "name": "https://jvn.jp/en/jp/JVN64806328/index.html",
                  "refsource": "MISC",
                  "url": "https://jvn.jp/en/jp/JVN64806328/index.html"
                },
                {
                  "name": "https://jvn.jp/jp/JVN64806328/index.html",
                  "refsource": "MISC",
                  "url": "https://jvn.jp/jp/JVN64806328/index.html"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2021-20877",
        "datePublished": "2022-02-08T10:30:31.000Z",
        "dateReserved": "2020-12-17T00:00:00.000Z",
        "dateUpdated": "2024-08-03T17:53:23.123Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }