First published: Thu May 11 2023(Updated: )
Improper Authentication of RemoteUI of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger unauthorized access to the product. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier sold in US. i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF, C1127i firmware Ver.11.04 and earlier sold in Europe.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Canon MF642Cdw | <=11.04 | |
Canon MF642Cdw Firmware | ||
Canon MF644Cdw Firmware | <=11.04 | |
Canon imageCLASS MF644Cdw | ||
Canon MF741Cdw Firmware | <=11.04 | |
Canon MF741CDW | ||
Canon MF743Cdw Firmware | <=11.04 | |
Canon MF743Cdw Firmware | ||
Canon MF745Cdw Firmware | <=11.04 | |
Canon MF745Cdw Firmware | ||
Canon LBP621C Firmware | <=11.04 | |
Canon LBP621C Firmware | ||
Canon LBP622Cdw | <=11.04 | |
Canon LBP622C Firmware | ||
Canon LBP661C Firmware | <=11.04 | |
Canon LBP661C Firmware | ||
Canon LBP662C Firmware | <=11.04 | |
Canon LBP662C Firmware | ||
Canon LBP664C Firmware | <=11.04 | |
Canon LBP664C Firmware | ||
Canon MF1127C Firmware | <=11.04 | |
Canon MF1127C Firmware | ||
Canon MF262dw II Firmware | <=11.04 | |
Canon MF262dw II Firmware | ||
Canon MF264dw II Firmware | <=11.04 | |
Canon MF264dw II | ||
Canon MF267dw II Firmware | <=11.04 | |
Canon MF267dw II Firmware | ||
Canon MF269dw II | <=11.04 | |
Canon MF269dw II | ||
Canon MF269dw VP II Firmware | <=11.04 | |
Canon MF269dw VP II Firmware | ||
Canon MF272dw Firmware | <=11.04 | |
Canon MF272dw Firmware | ||
Canon MF273dw Firmware | <=11.04 | |
Canon MF273dw Firmware | ||
Canon MF275dw Firmware | <=11.04 | |
Canon MF275dw Firmware | ||
Canon MF641CW Firmware | <=11.04 | |
Canon MF641CW Firmware | ||
Canon MF746Cdw | <=11.04 | |
Canon MF746Cdw | ||
Canon LBP122dw Firmware | <=11.04 | |
Canon LBP122dw Firmware | ||
Canon LBP1127C | <=11.04 | |
Canon LBP1127C | ||
Canon LBP622Cdw | <=11.04 | |
Canon Color imageCLASS LBP622Cdw | ||
Canon LBP623CDW Firmware | <=11.04 | |
Canon LBP623CDW Firmware | ||
Canon LBP664CDW Firmware | <=11.04 | |
Canon LBP664CDW Firmware | ||
Canon imagePROGRAF TC-20 | <=11.04 | |
Canon imagePROGRAF TC-20 | ||
Canon imagePROGRAF TC-20M | <=11.04 | |
Canon imagePROGRAF TC-20M | ||
Canon Pixma G3270 Firmware | <=11.04 | |
Canon Pixma G3270 Firmware | ||
Canon Pixma G4270 | <=11.04 | |
Canon Pixma G4270 Firmware | ||
Canon Maxify GX3020 | <=11.04 | |
Canon Maxify GX3020 | ||
Canon Maxify GX4020 Firmware | <=11.04 | |
Canon Maxify GX4020 Firmware | ||
Canon i-SENSYS LBP621CW Firmware | <=11.04 | |
Canon i-SENSYS LBP621CW Firmware | ||
Canon i-SENSYS LBP623Cdw | <=11.04 | |
Canon i-SENSYS LBP623Cdw Firmware | ||
Canon i-SENSYS LBP633Cdw | <=11.04 | |
canon Color imageCLASS LBP633Cdw | ||
Canon i-SENSYS LBP664Cx | <=11.04 | |
Canon i-SENSYS LBP664Cx Firmware | ||
Canon i-SENSYS MF641CW | <=11.04 | |
Canon i-SENSYS MF641CW Firmware | ||
Canon i-SENSYS MF643Cdw Firmware | <=11.04 | |
Canon i-SENSYS MF643Cdw Firmware | ||
Canon i-SENSYS MF645Cx | <=11.04 | |
Canon i-SENSYS MF645Cx | ||
Canon i-SENSYS MF742CDW | <=11.04 | |
Canon i-SENSYS MF742CDW | ||
Canon i-SENSYS MF744Cdw | <=11.04 | |
Canon i-SENSYS MF744Cdw | ||
Canon i-SENSYS MF746Cx Firmware | <=11.04 | |
Canon i-SENSYS MF746Cx Firmware | ||
Canon i-SENSYS X C1127i firmware | <=11.04 | |
Canon i-SENSYS C1127i | ||
Canon i-SENSYS X C1127i firmware | <=11.04 | |
Canon i-SENSYS X C1127i | ||
Canon i-SENSYS X C1127P firmware | <=11.04 | |
Canon i-SENSYS X C1127P firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0858 is categorized as a moderate severity vulnerability due to improper authentication allowing unauthorized access on impacted devices.
To remediate CVE-2023-0858, users should update the firmware of affected Canon multifunction printers to the latest version that addresses the vulnerability.
CVE-2023-0858 impacts several Canon multifunction printers and laser printers running firmware version 11.04 or earlier.
An attacker exploiting CVE-2023-0858 could gain unauthorized access to the printer's functionality, potentially leading to data exposure or service disruption.
While the best practice is to update the firmware, temporarily isolating the affected printer from the network can help mitigate exposure until an update is applied.