CVE-2024-45320 is an out-of-bounds write vulnerability affecting specific Fuji Xerox DocuPrint CP and CM series multifunction printers, including models CP225w, CP228w, CM225fw, and CM228fw with firmware versions 01.22.01/01.10.01 and earlier. This medium-severity vulnerability (CVSS 6.5) can be exploited by an unauthenticated attacker on the adjacent network by processing a specially crafted printer job file, leading to a denial-of-service condition. There is currently no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| FUJIFILM Business Innovation Corp. | DocuPrint CM225fw | 01.10.01 and earlierCNA affected | |
| FUJIFILM Business Innovation Corp. | DocuPrint CM228fw | 01.10.01 and earlierCNA affected | |
| FUJIFILM Business Innovation Corp. | DocuPrint CP225w | 01.22.01 and earlierCNA affected | |
| FUJIFILM Business Innovation Corp. | DocuPrint CP228w | 01.22.01 and earlierCNA affected |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.