ZDI-CAN-19756: ZDI-23-555: (Pwn2Own) Canon imageCLASS MF743Cdw IPP number-up Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF743Cdw printers. Authentication is not required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-19756?
The severity of ZDI-CAN-19756 is critical due to the potential for arbitrary code execution by network-adjacent attackers.
How do I fix ZDI-CAN-19756?
To fix ZDI-CAN-19756, update your Canon imageCLASS MF743Cdw printer firmware to the latest version provided by Canon.
Who is affected by ZDI-CAN-19756?
Users of Canon imageCLASS MF743Cdw printers are affected by ZDI-CAN-19756 without needing authentication for exploitation.
What type of attack does ZDI-CAN-19756 allow?
ZDI-CAN-19756 allows network-adjacent attackers to execute arbitrary code on the affected printer.
Is authentication required to exploit ZDI-CAN-19756?
No, authentication is not required to exploit ZDI-CAN-19756, making it particularly dangerous for users.