CWE
287 284
Advisory Published
Updated

CVE-2023-0858

First published: Thu May 11 2023(Updated: )

Improper Authentication of RemoteUI of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger unauthorized access to the product. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier sold in US. i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF, C1127i firmware Ver.11.04 and earlier sold in Europe.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Canon MF642Cdw<=11.04
Canon MF642Cdw Firmware
Canon MF644Cdw Firmware<=11.04
Canon imageCLASS MF644Cdw
Canon MF741Cdw Firmware<=11.04
Canon MF741CDW
Canon MF743Cdw Firmware<=11.04
Canon MF743Cdw Firmware
Canon MF745Cdw Firmware<=11.04
Canon MF745Cdw Firmware
Canon LBP621C Firmware<=11.04
Canon LBP621C Firmware
Canon LBP622Cdw<=11.04
Canon LBP622C Firmware
Canon LBP661C Firmware<=11.04
Canon LBP661C Firmware
Canon LBP662C Firmware<=11.04
Canon LBP662C Firmware
Canon LBP664C Firmware<=11.04
Canon LBP664C Firmware
Canon MF1127C Firmware<=11.04
Canon MF1127C Firmware
Canon MF262dw II Firmware<=11.04
Canon MF262dw II Firmware
Canon MF264dw II Firmware<=11.04
Canon MF264dw II
Canon MF267dw II Firmware<=11.04
Canon MF267dw II Firmware
Canon MF269dw II<=11.04
Canon MF269dw II
Canon MF269dw VP II Firmware<=11.04
Canon MF269dw VP II Firmware
Canon MF272dw Firmware<=11.04
Canon MF272dw Firmware
Canon MF273dw Firmware<=11.04
Canon MF273dw Firmware
Canon MF275dw Firmware<=11.04
Canon MF275dw Firmware
Canon MF641CW Firmware<=11.04
Canon MF641CW Firmware
Canon MF746Cdw<=11.04
Canon MF746Cdw
Canon LBP122dw Firmware<=11.04
Canon LBP122dw Firmware
Canon LBP1127C<=11.04
Canon LBP1127C
Canon LBP622Cdw<=11.04
Canon Color imageCLASS LBP622Cdw
Canon LBP623CDW Firmware<=11.04
Canon LBP623CDW Firmware
Canon LBP664CDW Firmware<=11.04
Canon LBP664CDW Firmware
Canon imagePROGRAF TC-20<=11.04
Canon imagePROGRAF TC-20
Canon imagePROGRAF TC-20M<=11.04
Canon imagePROGRAF TC-20M
Canon Pixma G3270 Firmware<=11.04
Canon Pixma G3270 Firmware
Canon Pixma G4270<=11.04
Canon Pixma G4270 Firmware
Canon Maxify GX3020<=11.04
Canon Maxify GX3020
Canon Maxify GX4020 Firmware<=11.04
Canon Maxify GX4020 Firmware
Canon i-SENSYS LBP621CW Firmware<=11.04
Canon i-SENSYS LBP621CW Firmware
Canon i-SENSYS LBP623Cdw<=11.04
Canon i-SENSYS LBP623Cdw Firmware
Canon i-SENSYS LBP633Cdw<=11.04
canon Color imageCLASS LBP633Cdw
Canon i-SENSYS LBP664Cx<=11.04
Canon i-SENSYS LBP664Cx Firmware
Canon i-SENSYS MF641CW<=11.04
Canon i-SENSYS MF641CW Firmware
Canon i-SENSYS MF643Cdw Firmware<=11.04
Canon i-SENSYS MF643Cdw Firmware
Canon i-SENSYS MF645Cx<=11.04
Canon i-SENSYS MF645Cx
Canon i-SENSYS MF742CDW<=11.04
Canon i-SENSYS MF742CDW
Canon i-SENSYS MF744Cdw<=11.04
Canon i-SENSYS MF744Cdw
Canon i-SENSYS MF746Cx Firmware<=11.04
Canon i-SENSYS MF746Cx Firmware
Canon i-SENSYS X C1127i firmware<=11.04
Canon i-SENSYS C1127i
Canon i-SENSYS X C1127i firmware<=11.04
Canon i-SENSYS X C1127i
Canon i-SENSYS X C1127P firmware<=11.04
Canon i-SENSYS X C1127P firmware

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2023-0858?

    CVE-2023-0858 is categorized as a moderate severity vulnerability due to improper authentication allowing unauthorized access on impacted devices.

  • How do I fix CVE-2023-0858?

    To remediate CVE-2023-0858, users should update the firmware of affected Canon multifunction printers to the latest version that addresses the vulnerability.

  • Which devices are affected by CVE-2023-0858?

    CVE-2023-0858 impacts several Canon multifunction printers and laser printers running firmware version 11.04 or earlier.

  • What might an attacker achieve with CVE-2023-0858?

    An attacker exploiting CVE-2023-0858 could gain unauthorized access to the printer's functionality, potentially leading to data exposure or service disruption.

  • Is there a workaround for CVE-2023-0858 if I can't update immediately?

    While the best practice is to update the firmware, temporarily isolating the affected printer from the network can help mitigate exposure until an update is applied.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203