CVE-2024-2184: Buffer Overflow
Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers() which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.:Satera MF740C Series/Satera MF640C Series/Satera LBP660C Series/Satera LBP620C Series firmware v12.07 and earlier, and Satera MF750C Series/Satera LBP670C Series firmware v03.09 and earlier sold in Japan.Color imageCLASS MF740C Series/Color imageCLASS MF640C Series/Color imageCLASS X MF1127C/Color imageCLASS LBP664Cdw/Color imageCLASS LBP622Cdw/Color imageCLASS X LBP1127C firmware v12.07 and earlier, and Color imageCLASS MF750C Series/Color imageCLASS X MF1333C/Color imageCLASS LBP674Cdw/Color imageCLASS X LBP1333C firmware v03.09 and earlier sold in US.i-SENSYS MF740C Series/i-SENSYS MF640C Series/C1127i Series/i-SENSYS LBP660C Series/i-SENSYS LBP620C Series/C1127P firmware v12.07 and earlier, and i-SENSYS MF750C Series/C1333i Series/i-SENSYS LBP673Cdw/C1333P firmware v03.09 and earlier sold in Europe.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2184?
CVE-2024-2184 is categorized as a high severity vulnerability due to its potential to allow attackers to execute arbitrary code on affected devices.
Which devices are affected by CVE-2024-2184?
CVE-2024-2184 affects multiple Canon Satera and Color imageCLASS printer models, including the MF740C and MF640C series, with specific firmware versions.
How do I fix CVE-2024-2184?
To remediate CVE-2024-2184, users should update their affected Canon printers and multifunction devices to the latest firmware available from Canon.
What types of attacks can exploit CVE-2024-2184?
CVE-2024-2184 can be exploited by attackers on the same network segment to trigger device unresponsiveness or execute malicious code.
What is the root cause of CVE-2024-2184?
The root cause of CVE-2024-2184 is a buffer overflow vulnerability in the identifier field during the WSD probe request processing.