Buffer overflow in Address Book attribute tag processing on Small Office Multifunction Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold in Japan.Color imageCLASS LBP630C/Color imageCLASS MF650C Series/imageCLASS LBP230 Series/imageCLASS X LBP1238 II/imageCLASS MF450 Series/imageCLASS X MF1238 II/imageCLASS X MF1643i II/imageCLASS X MF1643iF II firmware v06.02 and earlier sold in US.i-SENSYS LBP630C Series/i-SENSYS MF650C Series/i-SENSYS LBP230 Series/1238P II/1238Pr II/i-SENSYS MF450 Series/i-SENSYS MF550 Series/1238i II/1238iF II/imageRUNNER 1643i II/imageRUNNER 1643iF II firmware v06.02 and earlier sold in Europe.
The vulnerability (CWE-787 — out-of-bounds buffer write) lies in the Address Book attribute tag processing mechanism. An attacker present in the same network segment can send specially crafted data that causes a buffer overflow in the device's memory. As a result, it is possible to overwrite memory areas beyond the intended buffer, leading to device instability or arbitrary code execution (RCE). The attack requires no authentication or user interaction.
An attacker can execute arbitrary code on the device (RCE) or cause its complete unavailability (no response), leading to loss of confidentiality, integrity, and system availability.
Device firmware should be updated to a version newer than v06.02, applying patches available from the manufacturer according to references: https://psirt.canon/advisory-information/cp2026-001/ (globally), https://canon.jp/support/support-info/260115vulnerability-response (Japan), https://www.usa.canon.com/support/canon-product-advisories/ (USA), https://www.canon-europe.com/support/product-security/ (Europe). Until patches are deployed, it is recommended to isolate devices in a dedicated network segment and restrict network access to printers only for authorized hosts.
Canon devices with firmware v06.02 and earlier: Satera LBP670C Series / Satera MF750C Series (Japan); Color imageCLASS LBP630C / Color imageCLASS MF650C Series / imageCLASS LBP230 Series / imageCLASS X LBP1238 II / imageCLASS MF450 Series / imageCLASS X MF1238 II / imageCLASS X MF1643i II / imageCLASS X MF1643iF II (USA); i-SENSYS LBP630C Series / i-SENSYS MF650C Series / i-SENSYS LBP230 Series / 1238P II / 1238Pr II / i-SENSYS MF450 Series / i-SENSYS MF550 Series / 1238i II / 1238iF II / imageRUNNER 1643i II / imageRUNNER 1643iF II (Europe). Also affects: Canon MF455DW, MF453DW, MF452DW.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCanon Lbp1238 Ii
HWCanonall versionsCanon Lbp1238 Ii Firmware
OSCanon≤ 06.02Canon Lbp236dw
HWCanonall versionsCanon Lbp236dw Firmware
OSCanon≤ 06.02Canon Lbp237dw
HWCanonall versionsCanon Lbp237dw Firmware
OSCanon≤ 06.02Canon Lbp632cdw
HWCanonall versionsCanon Lbp632cdw Firmware
OSCanon≤ 06.02Canon Lbp633cdw
HWCanonall versionsCanon Lbp633cdw Firmware
OSCanon≤ 06.02Canon Mf1238 Ii
HWCanonall versionsCanon Mf1238 Ii Firmware
OSCanon≤ 06.02Canon Mf1643if Ii
HWCanonall versionsCanon Mf1643if Ii Firmware
OSCanon≤ 06.02Canon Mf1643i Ii
HWCanonall versionsCanon Mf1643i Ii Firmware
OSCanon≤ 06.02Canon Mf451dw
HWCanonall versionsCanon Mf451dw Firmware
OSCanon≤ 06.02Canon Mf452dw
HWCanonall versionsCanon Mf452dw Firmware
OSCanon≤ 06.02Canon Mf453dw
HWCanonall versionsCanon Mf453dw Firmware
OSCanon≤ 06.02Canon Mf455dw
HWCanonall versionsCanon Mf455dw Firmware
OSCanon≤ 06.02Canon Mf652cdw
HWCanonall versionsCanon Mf652cw Firmware
OSCanon≤ 06.02Canon Mf653cdw
HWCanonall versionsCanon Mf653cdw Firmware
OSCanon≤ 06.02Canon Mf654cdw
HWCanonall versionsCanon Mf654cdw Firmware
OSCanon≤ 06.02
Related vulnerabilities
Buffer overflow w drukarkach Canon — RCE przez sieć lokalną
Buffer overflow w Canon — RCE przez WSD w drukarkach biurowych
Buffer overflow w przetwarzaniu XML plików XPS w drukarkach Canon
RCE przez invalid free w drukarkach Canon — luki w firmware v06.02
Buffer overflow w przetwarzaniu czcionek XPS w drukarkach Canon — RCE