CVE-2024-2184 is a critical buffer overflow vulnerability affecting various Canon Small Office Multifunction and Laser Printers, including specific Satera, Color imageCLASS, and i-SENSYS series models with outdated firmware. An unauthenticated attacker on the same network segment can exploit this flaw by sending a crafted WSD probe request, leading to denial-of-service or arbitrary code execution on the affected device. Rated with a CVSS score of 9.8 (Critical), this vulnerability requires no user interaction and has a low attack complexity, allowing for complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB) is currently unavailable. Despite the lack of active exploitation or public exploits, the vulnerability has garnered some community discussion, with 10 mentions across various platforms. Organizations are advised to update affected devices to the latest firmware versions to mitigate this significant risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Canon Inc. | C1127P | v12.07 and earlierCNA affected | |
| Canon Inc. | C1127i Series | v12.07 and earlierCNA affected | |
| Canon Inc. | C1333P | v03.09 and earlierCNA affected | |
| Canon Inc. | C1333i Series | v03.09 and earlierCNA affected | |
| Canon Inc. | Color ImageCLASS LBP622Cdw | v12.07 and earlierCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.