First published: Tue Mar 28 2023(Updated: )
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the privet API. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15834.
Credit: zdi-disclosures@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Canon imageCLASS MF644Cdw | ||
Canon D1620 Firmware | ||
Canon D1620 | ||
Canon D1650 Firmware | ||
Canon D1650 | ||
Canon D1520 Firmware | ||
Canon D1520 | ||
Canon D1550 Firmware | ||
Canon D1550 | ||
Canon Mf1127c Firmware | ||
Canon Mf1127c | ||
Canon Mf1238 Firmware | ||
Canon Mf1238 | ||
Canon Mf1238 Ii Firmware | ||
Canon Mf1238 Ii | ||
Canon Mf1643i Ii Firmware | ||
Canon Mf1643i Ii | ||
Canon Mf1643if Ii Firmware | ||
Canon Mf1643if Ii | ||
Canon Mf414dw Firmware | ||
Canon Mf414dw | ||
Canon Mf416dw Firmware | ||
Canon Mf416dw | ||
Canon Mf419dw Firmware | ||
Canon Mf419dw | ||
Canon Mf515dw Firmware | ||
Canon Mf515dw | ||
Canon Mf424dw Firmware | ||
Canon Mf424dw | ||
Canon Mf426dw Firmware | ||
Canon Mf426dw | ||
Canon Mf429dw Firmware | ||
Canon Mf429dw | ||
Canon Mf525dw Firmware | ||
Canon Mf525dw | ||
Canon Mf445dw Firmware | ||
Canon Mf445dw | ||
Canon Mf448dw Firmware | ||
Canon Mf448dw | ||
Canon Mf449dw Firmware | ||
Canon Mf449dw | ||
Canon Mf543dw Firmware | ||
Canon Mf543dw | ||
Canon Mf451dw Firmware | ||
Canon Mf451dw | ||
Canon Mf452dw Firmware | ||
Canon Mf452dw | ||
Canon Mf453dw Firmware | ||
Canon Mf453dw | ||
Canon Mf455dw Firmware | ||
Canon Mf455dw | ||
Canon Mf6160dw Firmware | ||
Canon Mf6160dw | ||
Canon Mf6180dw Firmware | ||
Canon Mf6180dw | ||
Canon Mf624cdw Firmware | ||
Canon Mf624cdw | ||
Canon Mf628cdw Firmware | ||
Canon Mf628cdw | ||
Canon Mf632cdw Firmware | ||
Canon Mf632cdw | ||
Canon Mf634cdw Firmware | ||
Canon Mf634cdw | ||
Canon Mf641cw Firmware | ||
Canon Mf641cw | ||
Canon Mf642cdw Firmware | ||
Canon Mf642cdw | ||
Canon Mf644cdw Firmware | ||
Canon Mf644cdw | ||
Canon Mf726cdw Firmware | ||
Canon Mf726cdw | ||
Canon Mf729cdw Firmware | ||
Canon Mf729cdw | ||
Canon Mf731cdw Firmware | ||
Canon Mf731cdw | ||
Canon Mf733cdw Firmware | ||
Canon Mf733cdw | ||
Canon Mf735cdw Firmware | ||
Canon Mf735cdw | ||
Canon Mf741cdw Firmware | ||
Canon Mf741cdw | ||
Canon Mf743cdw Firmware | ||
Canon Mf743cdw | ||
Canon Mf745cdw Firmware | ||
Canon Mf745cdw | ||
Canon Mf746cdw Firmware | ||
Canon Mf746cdw | ||
Canon Mf810cdn Firmware | ||
Canon Mf810cdn | ||
Canon Mf820cdn Firmware | ||
Canon Mf820cdn | ||
Canon Mf8280cw Firmware | ||
Canon Mf8280cw | ||
Canon Mf8580cdw Firmware | ||
Canon Mf8580cdw | ||
Canon Lbp1127c Firmware | ||
Canon Lbp1127c | ||
Canon Lbp1238 Firmware | ||
Canon Lbp1238 | ||
Canon Lbp1238 Ii Firmware | ||
Canon Lbp1238 Ii | ||
Canon Lbp214dw Firmware | ||
Canon Lbp214dw | ||
Canon Lbp215dw Firmware | ||
Canon Lbp215dw | ||
Canon Lbp226dw Firmware | ||
Canon Lbp226dw | ||
Canon Lbp227dw Firmware | ||
Canon Lbp227dw | ||
Canon Lbp228dw Firmware | ||
Canon Lbp228dw | ||
Canon Lbp236dw Firmware | ||
Canon Lbp236dw | ||
Canon Lbp237dw Firmware | ||
Canon Lbp237dw | ||
Canon Lbp251dw Firmware | ||
Canon Lbp251dw | ||
Canon Lbp253dw Firmware | ||
Canon Lbp253dw | ||
Canon Lbp612cdw Firmware | ||
Canon Lbp612cdw | ||
Canon Lbp622cdw Firmware | ||
Canon Lbp622cdw | ||
Canon Lbp623cdw Firmware | ||
Canon Lbp623cdw | ||
Canon Lbp654cdw Firmware | ||
Canon Lbp654cdw | ||
Canon Lbp664cdw Firmware | ||
Canon Lbp664cdw | ||
Canon Ir1435i Firmware | ||
Canon Ir1435i | ||
Canon 1435if Firmware | ||
Canon 1435if | ||
Canon 1435p Firmware | ||
Canon 1435p | ||
Canon 1435i\+ Firmware | ||
Canon 1435i\+ | ||
Canon 1435if\+ Firmware | ||
Canon 1435if\+ | ||
Canon 1435p\+ Firmware | ||
Canon 1435p\+ | ||
Canon Ir1643i Firmware | ||
Canon Ir1643i | ||
Canon Ir1643if Firmware | ||
Canon Ir1643if | ||
Canon Wg7240 Firmware | ||
Canon Wg7240 | ||
Canon Wg7250 Firmware | ||
Canon Wg7250 | ||
Canon Wg7250f Firmware | ||
Canon Wg7250f | ||
Canon Wg7250z Firmware | ||
Canon Wg7250z |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24674 is a Stack-based Buffer Overflow Remote Code Execution Vulnerability affecting Canon imageCLASS MF644Cdw printers.
No, authentication is not required to exploit CVE-2022-24674 vulnerability.
The severity of CVE-2022-24674 vulnerability is rated as high with a CVSS score of 8.8.
To fix CVE-2022-24674, apply the necessary security patches provided by Canon.
More information about CVE-2022-24674 can be found on the official Canon product advisories page and Zero Day Initiative advisories.