First published: Thu May 11 2023(Updated: )
Buffer overflow in IPP number-up attribute process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier sold in US. i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF, C1127i firmware Ver.11.04 and earlier sold in Europe.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Canon MF642Cdw | <=11.04 | |
Canon MF642Cdw Firmware | ||
Canon MF644Cdw Firmware | <=11.04 | |
Canon imageCLASS MF644Cdw | ||
Canon MF741Cdw Firmware | <=11.04 | |
Canon MF741CDW | ||
Canon MF743Cdw Firmware | <=11.04 | |
Canon MF743Cdw Firmware | ||
Canon MF745Cdw Firmware | <=11.04 | |
Canon MF745Cdw Firmware | ||
Canon LBP621C Firmware | <=11.04 | |
Canon LBP621C Firmware | ||
Canon LBP622Cdw | <=11.04 | |
Canon LBP622C Firmware | ||
Canon LBP661C Firmware | <=11.04 | |
Canon LBP661C Firmware | ||
Canon LBP662C Firmware | <=11.04 | |
Canon LBP662C Firmware | ||
Canon LBP664C Firmware | <=11.04 | |
Canon LBP664C Firmware | ||
Canon MF1127C Firmware | <=11.04 | |
Canon MF1127C Firmware | ||
Canon MF262dw II Firmware | <=11.04 | |
Canon MF262dw II Firmware | ||
Canon MF264dw II Firmware | <=11.04 | |
Canon MF264dw II | ||
Canon MF267dw II Firmware | <=11.04 | |
Canon MF267dw II Firmware | ||
Canon MF269dw II | <=11.04 | |
Canon MF269dw II | ||
Canon MF269dw VP II Firmware | <=11.04 | |
Canon MF269dw VP II Firmware | ||
Canon MF272dw Firmware | <=11.04 | |
Canon MF272dw Firmware | ||
Canon MF273dw Firmware | <=11.04 | |
Canon MF273dw Firmware | ||
Canon MF275dw Firmware | <=11.04 | |
Canon MF275dw Firmware | ||
Canon MF641CW Firmware | <=11.04 | |
Canon MF641CW Firmware | ||
Canon MF746Cdw | <=11.04 | |
Canon MF746Cdw | ||
Canon LBP122dw Firmware | <=11.04 | |
Canon LBP122dw Firmware | ||
Canon LBP1127C | <=11.04 | |
Canon LBP1127C | ||
Canon LBP622Cdw | <=11.04 | |
Canon Color imageCLASS LBP622Cdw | ||
Canon LBP623CDW Firmware | <=11.04 | |
Canon LBP623CDW Firmware | ||
Canon LBP664CDW Firmware | <=11.04 | |
Canon LBP664CDW Firmware | ||
Canon imagePROGRAF TC-20 | <=11.04 | |
Canon imagePROGRAF TC-20 | ||
Canon imagePROGRAF TC-20M | <=11.04 | |
Canon imagePROGRAF TC-20M | ||
Canon Pixma G3270 Firmware | <=11.04 | |
Canon Pixma G3270 Firmware | ||
Canon Pixma G4270 | <=11.04 | |
Canon Pixma G4270 Firmware | ||
Canon Maxify GX3020 | <=11.04 | |
Canon Maxify GX3020 | ||
Canon Maxify GX4020 Firmware | <=11.04 | |
Canon Maxify GX4020 Firmware | ||
Canon i-SENSYS LBP621CW Firmware | <=11.04 | |
Canon i-SENSYS LBP621CW Firmware | ||
Canon i-SENSYS LBP623Cdw | <=11.04 | |
Canon i-SENSYS LBP623Cdw Firmware | ||
Canon i-SENSYS LBP633Cdw | <=11.04 | |
canon Color imageCLASS LBP633Cdw | ||
Canon i-SENSYS LBP664Cx | <=11.04 | |
Canon i-SENSYS LBP664Cx Firmware | ||
Canon i-SENSYS MF641CW | <=11.04 | |
Canon i-SENSYS MF641CW Firmware | ||
Canon i-SENSYS MF643Cdw Firmware | <=11.04 | |
Canon i-SENSYS MF643Cdw Firmware | ||
Canon i-SENSYS MF645Cx | <=11.04 | |
Canon i-SENSYS MF645Cx | ||
Canon i-SENSYS MF742CDW | <=11.04 | |
Canon i-SENSYS MF742CDW | ||
Canon i-SENSYS MF744Cdw | <=11.04 | |
Canon i-SENSYS MF744Cdw | ||
Canon i-SENSYS MF746Cx Firmware | <=11.04 | |
Canon i-SENSYS MF746Cx Firmware | ||
Canon i-SENSYS X C1127i firmware | <=11.04 | |
Canon i-SENSYS C1127i | ||
Canon i-SENSYS X C1127i firmware | <=11.04 | |
Canon i-SENSYS X C1127i | ||
Canon i-SENSYS X C1127P firmware | <=11.04 | |
Canon i-SENSYS X C1127P firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0855 is considered a critical vulnerability due to its potential for remote code execution and denial of service.
To mitigate CVE-2023-0855, update the affected Canon printer firmware to the latest version above 11.04.
CVE-2023-0855 affects several models of Canon multifunction printers and laser printers with firmware versions up to 11.04.
If exploited, CVE-2023-0855 can lead to crashing the printer or executing arbitrary code remotely.
As of now, there is no public indication that CVE-2023-0855 is being actively exploited in the wild, but it remains a serious risk.