CVE-2023-0858

LOW

Canon MF/LBP Series Firmware < 11.04 - Unauthenticated Improper Access Control

Title source: llm
STIX 2.1

Description

Improper Authentication of RemoteUI of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger unauthorized access to the product. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier sold in US. i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF, C1127i firmware Ver.11.04 and earlier sold in Europe.

Scores

CVSS v3 3.1
EPSS 0.0057
EPSS Percentile 42.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284 CWE-287
Status published
Products (45)
canon/i-sensys_lbp621cw_firmware < 11.04
canon/i-sensys_lbp623cdw_firmware < 11.04
canon/i-sensys_lbp633cdw_firmware < 11.04
canon/i-sensys_lbp664cx_firmware < 11.04
canon/i-sensys_mf641cw_firmware < 11.04
canon/i-sensys_mf643cdw_firmware < 11.04
canon/i-sensys_mf645cx_firmware < 11.04
canon/i-sensys_mf742cdw_firmware < 11.04
canon/i-sensys_mf744cdw_firmware < 11.04
canon/i-sensys_mf746cx_firmware < 11.04
... and 35 more
Published May 11, 2023
Tracked Since Feb 18, 2026