CVE-2023-6232 is a critical buffer overflow vulnerability affecting specific Canon Office Multifunction Printers and Laser Printers, including models sold in Japan, the US, and Europe. An unauthenticated attacker on the same network segment can exploit this flaw in the Address Book username process during authentication. Successful exploitation could lead to the device becoming unresponsive (denial of service) or allow for arbitrary code execution with a CVSS score of 9.8 (Critical). While there is no known active exploitation or publicly available exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community attention with 11 mentions, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 03.07CPE matchmatch criteria | cpe:2.3:o:canon:mf755cdw_firmware:*:*:*:*:*:*:*:* | ||
<= 03.07CPE matchmatch criteria | cpe:2.3:o:canon:mf753cdw_firmware:*:*:*:*:*:*:*:* | ||
<= 03.07CPE matchmatch criteria | cpe:2.3:o:canon:mf751cdw_firmware:*:*:*:*:*:*:*:* | ||
<= 03.07CPE matchmatch criteria | cpe:2.3:o:canon:lbp674c_firmware:*:*:*:*:*:*:*:* | ||
<= 03.07CPE matchmatch criteria | cpe:2.3:o:canon:lbp672c_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.