TROYANOSYVIRUS
Retour aux CVEs

CVE-2024-12648

CRITICAL
9.8

Description

Buffer overflow in TIFF data EXIF tag processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw firmware v05.04 and earlier sold in Japan. Color imageCLASS MF656Cdw/Color imageCLASS MF654Cdw/Color imageCLASS MF653Cdw/Color imageCLASS MF652Cdw/Color imageCLASS LBP633Cdw/Color imageCLASS LBP632Cdw firmware v05.04 and earlier sold in US. i-SENSYS MF657Cdw/i-SENSYS MF655Cdw/i-SENSYS MF651Cdw/i-SENSYS LBP633Cdw/i-SENSYS LBP631Cdw firmware v05.04 and earlier sold in Europe.

Details CVE

Score CVSS v3.19.8
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie1/28/2025
Derniere modification1/26/2026
Sourcenvd
Observations honeypot0

Produits affectes

canon:lbp1238_iicanon:lbp1238_ii_firmwarecanon:lbp1440canon:lbp1440_firmwarecanon:lbp236dwcanon:lbp236dw_firmwarecanon:lbp237dwcanon:lbp237dw_firmwarecanon:lbp246dwcanon:lbp246dw_firmwarecanon:lbp247dwcanon:lbp247dw_firmwarecanon:lbp632cdwcanon:lbp632cdw_firmwarecanon:lbp633cdwcanon:lbp633cdw_firmwarecanon:mf1238_iicanon:mf1238_ii_firmwarecanon:mf1440canon:mf1440_firmwarecanon:mf1643i_iicanon:mf1643i_ii_firmwarecanon:mf1643if_iicanon:mf1643if_ii_firmwarecanon:mf451dwcanon:mf451dw_firmwarecanon:mf452dwcanon:mf452dw_firmwarecanon:mf453dwcanon:mf453dw_firmwarecanon:mf455dwcanon:mf455dw_firmwarecanon:mf462dwcanon:mf462dw_firmwarecanon:mf465dwcanon:mf465dw_firmwarecanon:mf652cwcanon:mf652cw_firmwarecanon:mf653cdwcanon:mf653cdw_firmwarecanon:mf654cdwcanon:mf654cdw_firmwarecanon:mf656cdwcanon:mf656cdw_firmware

Faiblesses (CWE)

CWE-787

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.