CVE-2024-2184

CRITICAL

Satera Printers <v12.07/v03.09 - Buffer Overflow

Title source: llm
STIX 2.1

Description

Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF740C Series/Satera MF640C Series/Satera LBP660C Series/Satera LBP620C Series firmware v12.07 and earlier, and Satera MF750C Series/Satera LBP670C Series firmware v03.09 and earlier sold in Japan.Color imageCLASS MF740C Series/Color imageCLASS MF640C Series/Color imageCLASS X MF1127C/Color imageCLASS LBP664Cdw/Color imageCLASS LBP622Cdw/Color imageCLASS X LBP1127C firmware v12.07 and earlier, and Color imageCLASS MF750C Series/Color imageCLASS X MF1333C/Color imageCLASS LBP674Cdw/Color imageCLASS X LBP1333C firmware v03.09 and earlier sold in US.i-SENSYS MF740C Series/i-SENSYS MF640C Series/C1127i Series/i-SENSYS LBP660C Series/i-SENSYS LBP620C Series/C1127P firmware v12.07 and earlier, and i-SENSYS MF750C Series/C1333i Series/i-SENSYS LBP673Cdw/C1333P firmware v03.09 and earlier sold in Europe.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0081
EPSS Percentile 52.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-787
Status published
Products (26)
Canon Inc./C1127i Series v12.07 and earlier
Canon Inc./C1127P v12.07 and earlier
Canon Inc./C1333i Series v03.09 and earlier
Canon Inc./C1333P v03.09 and earlier
Canon Inc./Color imageCLASS LBP622Cdw v12.07 and earlier
Canon Inc./Color imageCLASS LBP664Cdw v12.07 and earlier
Canon Inc./Color imageCLASS LBP674Cdw v03.09 and earlier
Canon Inc./Color imageCLASS MF640C Series v12.07 and earlier
Canon Inc./Color imageCLASS MF740C Series v12.07 and earlier
Canon Inc./Color imageCLASS MF750C Series v03.09 and earlier
... and 16 more
Published Mar 11, 2024
Tracked Since Feb 18, 2026