CVE-2023-6233
published 2024-02-06CVE-2023-6233: Buffer overflow in SLP attribute request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to…
PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.38%
69.3th percentile
Buffer overflow in SLP attribute request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canon | i-sensys_lbp673cdw_firmware | <= 03.07 | — |
| canon | i-sensys_mf752cdw_firmware | <= 03.07 | — |
| canon | i-sensys_mf754cdw_firmware | <= 03.07 | — |
| canon | i-sensys_x_c1333i_firmware | <= 03.07 | — |
| canon | i-sensys_x_c1333if_firmware | <= 03.07 | — |
| canon | i-sensys_x_c1333p_firmware | <= 03.07 | — |
| canon | lbp122dw_firmware | <= 03.07 | — |
| canon | lbp1238_ii_firmware | <= 03.07 | — |
| canon | lbp1333c_firmware | <= 03.07 | — |
| canon | lbp236dw_firmware | <= 03.07 | — |
| canon | lbp237dw_firmware | <= 03.07 | — |
| canon | lbp671c_firmware | <= 03.07 | — |
| canon | lbp672c_firmware | <= 03.07 | — |
| canon | lbp674c_firmware | <= 03.07 | — |
| canon | lbp674cdw_firmware | <= 03.07 | — |
| canon | mf1238_ii_firmware | <= 03.07 | — |
| canon | mf1333c_firmware | <= 03.07 | — |
| canon | mf1643i_ii_firmware | <= 03.07 | — |
| canon | mf1643if_ii_firmware | <= 03.07 | — |
| canon | mf272dw_firmware | <= 03.07 | — |
| canon | mf273dw_firmware | <= 03.07 | — |
| canon | mf275dw_firmware | <= 03.07 | — |
| canon | mf451dw_firmware | <= 03.07 | — |
| canon | mf452dw_firmware | <= 03.07 | — |
| canon | mf453dw_firmware | <= 03.07 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
net/mlx5e: TC, Fix using eswitch mapping in nic mode
osv·2025-12-30
CVE-2023-54216 net/mlx5e: TC, Fix using eswitch mapping in nic mode
net/mlx5e: TC, Fix using eswitch mapping in nic mode
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: TC, Fix using eswitch mapping in nic mode
Cited patch is using the eswitch object mapping pool while
in nic mode where it isn't initialized. This results in the
trace below [0].
Fix that by using either nic or eswitch object mapping pool
depending if eswitch is enabled or not.
[0]:
[ 826.446057] ==================================================================
[ 826.446729] BUG: KASAN: slab-use-after-free in mlx5_add_flow_rules+0x30/0x490 [mlx5_core]
[ 826.447515] Read of size 8 at addr ffff888194485830 by task tc/6233
[ 826.448243] CPU: 16 PID: 6233 Comm: tc Tainted: G W 6.3.0-rc6+ #1
[ 826.448890] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BI
GHSA
GHSA-99jr-pjjw-hqmq: Buffer overflow in SLP attribute request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network seg
ghsa_unreviewed·2024-02-06
CVE-2023-6233 [CRITICAL] CWE-787 GHSA-99jr-pjjw-hqmq: Buffer overflow in SLP attribute request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network seg
Buffer overflow in SLP attribute request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://canon.jp/support/support-info/240205vulnerability-responsehttps://psirt.canon/advisory-information/cp2024-001/https://www.canon-europe.com/support/product-security-latest-news/https://www.usa.canon.com/support/canon-product-advisories/Service-Notice-Regarding-Vulnerability-Measure-Against-Buffer-Overflow-for-Laser-Printers-and-Small-Office-Multifunctional-Printershttps://canon.jp/support/support-info/240205vulnerability-responsehttps://psirt.canon/advisory-information/cp2024-001/https://www.canon-europe.com/support/product-security-latest-news/https://www.usa.canon.com/support/canon-product-advisories/Service-Notice-Regarding-Vulnerability-Measure-Against-Buffer-Overflow-for-Laser-Printers-and-Small-Office-Multifunctional-Printers
2024-02-06
Published