ZDI-CAN-19798: ZDI-23-554: (Pwn2Own) Canon imageCLASS MF743Cdw cmNetBiosParseName Heap-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF743Cdw printers. Authentication is not required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-19798?
The severity of ZDI-CAN-19798 is critical due to its ability to allow arbitrary code execution without authentication.
How do I fix ZDI-CAN-19798?
To fix ZDI-CAN-19798, it is recommended to apply the latest firmware updates provided by Canon for the imageCLASS MF743Cdw printer.
Who is affected by ZDI-CAN-19798?
ZDI-CAN-19798 affects all installations of Canon imageCLASS MF743Cdw printers that have not been patched.
Can ZDI-CAN-19798 be exploited remotely?
Yes, ZDI-CAN-19798 can be exploited by network-adjacent attackers given the lack of authentication requirements.
What type of attacks can ZDI-CAN-19798 lead to?
ZDI-CAN-19798 can lead to arbitrary code execution attacks, which may compromise the affected printer's functionality and security.