Buffer overflow in CPCA list processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold in Japan.Color imageCLASS LBP630C/Color imageCLASS MF650C Series/imageCLASS LBP230 Series/imageCLASS X LBP1238 II/imageCLASS MF450 Series/imageCLASS X MF1238 II/imageCLASS X MF1643i II/imageCLASS X MF1643iF II firmware v06.02 and earlier sold in US.i-SENSYS LBP630C Series/i-SENSYS MF650C Series/i-SENSYS LBP230 Series/1238P II/1238Pr II/i-SENSYS MF450 Series/i-SENSYS MF550 Series/1238i II/1238iF II/imageRUNNER 1643i II/imageRUNNER 1643iF II firmware v06.02 and earlier sold in Europe.
A CWE-787 (out-of-bounds write) error occurs when processing CPCA protocol lists by the printer firmware. An attacker present in the same network segment can send crafted data that causes memory to be overwritten beyond the boundaries of the allocated buffer. This can result in device crash (unresponsiveness) or — in the case of controlled overwrite — arbitrary code execution in the context of the printer firmware. The attack requires no authentication or user interaction.
An attacker can cause permanent unavailability of the device or execute arbitrary code on the vulnerable printer, gaining full control over it, including access to processed documents and network configuration.
Device firmware should be updated to a version newer than v06.02 in accordance with the manufacturer's recommendations published in the references (canon.jp, psirt.canon, canon-europe.com, usa.canon.com). Until the update is applied, it is recommended to isolate printers in a dedicated network segment (VLAN) with restricted access only for authorized hosts and to block unauthorized network traffic directed to printing devices at the firewall level.
Firmware version v06.02 and earlier for the following product lines: Satera LBP670C Series / Satera MF750C Series (Japan); Color imageCLASS LBP630C / Color imageCLASS MF650C Series / imageCLASS LBP230 Series / imageCLASS X LBP1238 II / imageCLASS MF450 Series / imageCLASS X MF1238 II / imageCLASS X MF1643i II / imageCLASS X MF1643iF II (USA); i-SENSYS LBP630C Series / i-SENSYS MF650C Series / i-SENSYS LBP230 Series / 1238P II / 1238Pr II / i-SENSYS MF450 Series / i-SENSYS MF550 Series / 1238i II / 1238iF II / imageRUNNER 1643i II / imageRUNNER 1643iF II (Europe). In the context of reported products, it also affects Canon MF455DW, MF453DW, MF452DW.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCanon Lbp1238 Ii
HWCanonall versionsCanon Lbp1238 Ii Firmware
OSCanon≤ 06.02Canon Lbp236dw
HWCanonall versionsCanon Lbp236dw Firmware
OSCanon≤ 06.02Canon Lbp237dw
HWCanonall versionsCanon Lbp237dw Firmware
OSCanon≤ 06.02Canon Lbp632cdw
HWCanonall versionsCanon Lbp632cdw Firmware
OSCanon≤ 06.02Canon Lbp633cdw
HWCanonall versionsCanon Lbp633cdw Firmware
OSCanon≤ 06.02Canon Mf1238 Ii
HWCanonall versionsCanon Mf1238 Ii Firmware
OSCanon≤ 06.02Canon Mf1643if Ii
HWCanonall versionsCanon Mf1643if Ii Firmware
OSCanon≤ 06.02Canon Mf1643i Ii
HWCanonall versionsCanon Mf1643i Ii Firmware
OSCanon≤ 06.02Canon Mf451dw
HWCanonall versionsCanon Mf451dw Firmware
OSCanon≤ 06.02Canon Mf452dw
HWCanonall versionsCanon Mf452dw Firmware
OSCanon≤ 06.02Canon Mf453dw
HWCanonall versionsCanon Mf453dw Firmware
OSCanon≤ 06.02Canon Mf455dw
HWCanonall versionsCanon Mf455dw Firmware
OSCanon≤ 06.02Canon Mf652cdw
HWCanonall versionsCanon Mf652cw Firmware
OSCanon≤ 06.02Canon Mf653cdw
HWCanonall versionsCanon Mf653cdw Firmware
OSCanon≤ 06.02Canon Mf654cdw
HWCanonall versionsCanon Mf654cdw Firmware
OSCanon≤ 06.02
Related vulnerabilities
Buffer overflow w przetwarzaniu czcionek XPS w drukarkach Canon — RCE
Buffer overflow w Canon — RCE przez WSD w drukarkach biurowych
Buffer overflow w przetwarzaniu XML plików XPS w drukarkach Canon
RCE przez invalid free w drukarkach Canon — luki w firmware v06.02
Buffer overflow w drukarkach Canon — RCE przez sieć lokalną