CVE-2023-0859: Medium severity canon mf642cdw vulnerability
Arbitrary Files can be installed in the Setting Data Import function of Office / Small Office Multifunction Printers and Laser Printers(). :Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier sold in US. i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF, C1127i firmware Ver.11.04 and earlier sold in Europe.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0859?
CVE-2023-0859 has been classified with a moderate severity due to the potential for arbitrary file installation through the affected printers' firmware.
How do I fix CVE-2023-0859?
To mitigate CVE-2023-0859, upgrade your printer firmware to version 11.05 or later, as this version addresses the vulnerability.
What products are affected by CVE-2023-0859?
CVE-2023-0859 affects various Canon multifunction printers and laser printers, particularly those with firmware version 11.04 or earlier.
Can CVE-2023-0859 be exploited remotely?
Yes, CVE-2023-0859 can be exploited remotely by an attacker who can send malicious files to the vulnerable printers.
Is there a workaround for CVE-2023-0859?
While upgrading firmware is the best solution, temporarily disabling the remote data import feature may serve as a workaround until the update can be applied.