ZDI-24-089: (Pwn2Own) Canon imageCLASS MF753Cdw CADM rmSetFileName Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF753Cdw printers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2023-6229.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-089?
The vulnerability ZDI-24-089 has a CVSS rating of 8.8, indicating high severity.
How does ZDI-24-089 affect Canon imageCLASS MF753Cdw printers?
ZDI-24-089 allows network-adjacent attackers to execute arbitrary code on affected Canon imageCLASS MF753Cdw printers without authentication.
What types of attacks can be executed due to ZDI-24-089?
Due to ZDI-24-089, attackers can perform remote code execution attacks on the vulnerable printers.
Is authentication required to exploit ZDI-24-089?
No, authentication is not required to exploit the vulnerability ZDI-24-089.
Which devices are impacted by ZDI-24-089?
The vulnerability ZDI-24-089 specifically affects Canon imageCLASS MF753Cdw printers.