2025-01-28 03:03:52 +00:00

68 lines
2.6 KiB
JSON

{
"id": "CVE-2024-12649",
"sourceIdentifier": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"published": "2025-01-28T01:15:08.823",
"lastModified": "2025-01-28T01:15:08.823",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Buffer overflow in XPS data font processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw firmware v05.04 and earlier sold in Japan. Color imageCLASS MF656Cdw/Color imageCLASS MF654Cdw/Color imageCLASS MF653Cdw/Color imageCLASS MF652Cdw/Color imageCLASS LBP633Cdw/Color imageCLASS LBP632Cdw firmware v05.04 and earlier sold in US. i-SENSYS MF657Cdw/i-SENSYS MF655Cdw/i-SENSYS MF651Cdw/i-SENSYS LBP633Cdw/i-SENSYS LBP631Cdw firmware v05.04 and earlier sold in Europe."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "f98c90f0-e9bd-4fa7-911b-51993f3571fd",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-787"
}
]
}
],
"references": [
{
"url": "https://canon.jp/support/support-info/250127vulnerability-response",
"source": "f98c90f0-e9bd-4fa7-911b-51993f3571fd"
},
{
"url": "https://psirt.canon/advisory-information/cp2025-001/",
"source": "f98c90f0-e9bd-4fa7-911b-51993f3571fd"
},
{
"url": "https://www.canon-europe.com/support/product-security/#news",
"source": "f98c90f0-e9bd-4fa7-911b-51993f3571fd"
},
{
"url": "https://www.usa.canon.com/support/canon-product-advisories/service-notice-regarding-vulnerability-measure-against-buffer-overflow-for-laser-printers-and-small-office-multifunctional-printers",
"source": "f98c90f0-e9bd-4fa7-911b-51993f3571fd"
}
]
}