CVE-2024-12647

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 28, 2025
CWE ID 787

Summary

CVE-2024-12647 is a buffer overflow vulnerability affecting Small Office Multifunction Printers and Laser Printers from Canon, including Satera MF656Cdw, Satera MF654Cdw, Color imageCLASS MF656Cdw, Color imageCLASS MF654Cdw, Color imageCLASS MF653Cdw, Color imageCLASS MF652Cdw, i-SENSYS MF657Cdw, i-SENSYS MF655Cdw, i-SENSYS MF651Cdw, i-SENSYS LBP633Cdw, and i-SENSYS LBP631Cdw. The issue lies in the CPCA font download processing and can be exploited by an attacker on the network segment to cause the affected product to become unresponsive or execute arbitrary code. The vulnerability affects firmware v05.04 and earlier, sold in Japan, the US, and Europe.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share