CVE-2024-2184

Description

Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF740C Series/Satera MF640C Series/Satera LBP660C Series/Satera LBP620C Series firmware v12.07 and earlier, and Satera MF750C Series/Satera LBP670C Series firmware v03.09 and earlier sold in Japan.Color imageCLASS MF740C Series/Color imageCLASS MF640C Series/Color imageCLASS X MF1127C/Color imageCLASS LBP664Cdw/Color imageCLASS LBP622Cdw/Color imageCLASS X LBP1127C firmware v12.07 and earlier, and Color imageCLASS MF750C Series/Color imageCLASS X MF1333C/Color imageCLASS LBP674Cdw/Color imageCLASS X LBP1333C firmware v03.09 and earlier sold in US.i-SENSYS MF740C Series/i-SENSYS MF640C Series/C1127i Series/i-SENSYS LBP660C Series/i-SENSYS LBP620C Series/C1127P firmware v12.07 and earlier, and i-SENSYS MF750C Series/C1333i Series/i-SENSYS LBP673Cdw/C1333P firmware v03.09 and earlier sold in Europe.

Category

9.8
CVSS
Severity: Critical
CVSS 3.1 •
EPSS 0.10%
Vendor Advisory psirt.canon
Affected: Canon Inc. Color imageCLASS MF740C Series
Affected: Canon Inc. Color imageCLASS MF640C Series
Affected: Canon Inc. i-SENSYS MF740C Series
Affected: Canon Inc. i-SENSYS MF640C Series
Affected: Canon Inc. Satera MF740C Series
Affected: Canon Inc. Satera MF640C Series
Affected: Canon Inc. Color imageCLASS X MF1127C
Affected: Canon Inc. C1127i Series
Affected: Canon Inc. Color imageCLASS LBP664Cdw
Affected: Canon Inc. Color imageCLASS LBP622Cdw
Affected: Canon Inc. i-SENSYS LBP660C Series
Affected: Canon Inc. i-SENSYS LBP620C Series
Affected: Canon Inc. Satera LBP660C Series
Affected: Canon Inc. Satera LBP620C Series
Affected: Canon Inc. Color imageCLASS X LBP1127C
Affected: Canon Inc. C1127P
Affected: Canon Inc. Color imageCLASS MF750C Series
Affected: Canon Inc. i-SENSYS MF750C Series
Affected: Canon Inc. Satera MF750C Series
Affected: Canon Inc. Color imageCLASS X MF1333C
Affected: Canon Inc. C1333i Series
Affected: Canon Inc. Color imageCLASS LBP674Cdw
Affected: Canon Inc. i-SENSYS LBP673Cdw
Affected: Canon Inc. Satera LBP670C Series
Affected: Canon Inc. Color imageCLASS X LBP1333C
Affected: Canon Inc. C1333P
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2024-2184?
CVE-2024-2184 has been scored as a critical severity vulnerability.
How to fix CVE-2024-2184?
To fix CVE-2024-2184, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2024-2184 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2024-2184 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2024-2184?
CVE-2024-2184 affects Canon Inc. Color imageCLASS MF740C Series, Canon Inc. Color imageCLASS MF640C Series, Canon Inc. i-SENSYS MF740C Series, Canon Inc. i-SENSYS MF640C Series, Canon Inc. Satera MF740C Series, Canon Inc. Satera MF640C Series, Canon Inc. Color imageCLASS X MF1127C, Canon Inc. C1127i Series, Canon Inc. Color imageCLASS LBP664Cdw, Canon Inc. Color imageCLASS LBP622Cdw, Canon Inc. i-SENSYS LBP660C Series, Canon Inc. i-SENSYS LBP620C Series, Canon Inc. Satera LBP660C Series, Canon Inc. Satera LBP620C Series, Canon Inc. Color imageCLASS X LBP1127C, Canon Inc. C1127P, Canon Inc. Color imageCLASS MF750C Series, Canon Inc. i-SENSYS MF750C Series, Canon Inc. Satera MF750C Series, Canon Inc. Color imageCLASS X MF1333C, Canon Inc. C1333i Series, Canon Inc. Color imageCLASS LBP674Cdw, Canon Inc. i-SENSYS LBP673Cdw, Canon Inc. Satera LBP670C Series, Canon Inc. Color imageCLASS X LBP1333C, Canon Inc. C1333P.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.