cbcvebase.
CVE-2024-0244
published 2024-02-06

CVE-2024-0244: Buffer overflow in CPCA PCFAX number process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to…

PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.38%
69.2th percentile
Buffer overflow in CPCA PCFAX number process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS MF750C Series/Color imageCLASS X MF1333C firmware v03.07 and earlier sold in US. i-SENSYS MF754Cdw/C1333iF firmware v03.07 and earlier sold in Europe.

Affected

12 ranges
VendorProductVersion rangeFixed in
canoni-sensys_mf754cdw_firmware<= 03.07
canoni-sensys_x_c1333if_firmware<= 03.07
canonlbp1333c_firmware<= 03.07
canonmf1333c_firmware<= 03.07
canonmf751cdw_firmware<= 03.07
canonmf753cdw_firmware<= 03.07
canonmf755cdw_firmware<= 03.07
canon_incc1333if
canon_inccolor_imageclass_mf750c_series
canon_inccolor_imageclass_x_mf1333c
canon_inci-sensys_mf754cdw
canon_incsatera_mf750c_series

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is a buffer overflow in the CPCA PCFAX number processing component of Canon multifunction/laser printers. Detection should focus on anomalous or oversized PCFAX number fields in network traffic targeting affected Canon printer models.
  • Attack vector is network-segment local (adjacent network); monitor for unexpected traffic or crash/unresponsive behavior on Canon Satera MF750C Series, Color imageCLASS MF750C Series/X MF1333C, and i-SENSYS MF754Cdw/C1333iF devices.
  • ·Affected firmware versions are v03.07 and earlier across three regional product lines: Satera MF750C Series (Japan), Color imageCLASS MF750C Series/Color imageCLASS X MF1333C (US), and i-SENSYS MF754Cdw/C1333iF (Europe). Scope detection/patching efforts to these specific firmware versions.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.