ZDI-24-562: Canon imageCLASS MF753Cdw setResource Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF753Cdw printers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2023-6234.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-562?
The vulnerability ZDI-24-562 has a CVSS rating of 8.8, indicating a critical severity level.
How do I fix ZDI-24-562?
To mitigate the risk posed by ZDI-24-562, update the firmware of the Canon imageCLASS MF753Cdw printer to the latest version.
Who can exploit ZDI-24-562?
Network-adjacent attackers can exploit ZDI-24-562 without the need for authentication.
What effect does ZDI-24-562 have on affected devices?
ZDI-24-562 allows attackers to execute arbitrary code on affected Canon imageCLASS MF753Cdw printers.
Is authentication required to exploit ZDI-24-562?
No, authentication is not required to exploit the ZDI-24-562 vulnerability.