5.3

CVE-2023-0859

Arbitrary Files can be installed in the Setting Data Import function of Office / Small Office Multifunction Printers and Laser Printers(*). *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier sold in US. i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF, C1127i firmware Ver.11.04 and earlier sold in Europe.

Data is provided by the National Vulnerability Database (NVD)
CanonMf642cdw Firmware Version <= 11.04
   CanonMf642cdw Version-
CanonMf644cdw Firmware Version <= 11.04
   CanonMf644cdw Version-
CanonMf741cdw Firmware Version <= 11.04
   CanonMf741cdw Version-
CanonMf743cdw Firmware Version <= 11.04
   CanonMf743cdw Version-
CanonMf745cdw Firmware Version <= 11.04
   CanonMf745cdw Version-
CanonLbp621c Firmware Version <= 11.04
   CanonLbp621c Version-
CanonLbp622c Firmware Version <= 11.04
   CanonLbp622c Version-
CanonLbp661c Firmware Version <= 11.04
   CanonLbp661c Version-
CanonLbp662c Firmware Version <= 11.04
   CanonLbp662c Version-
CanonLbp664c Firmware Version <= 11.04
   CanonLbp664c Version-
CanonMf1127c Firmware Version <= 11.04
   CanonMf1127c Version-
CanonMf262dw Ii Firmware Version <= 11.04
   CanonMf262dw Ii Version-
CanonMf264dw Ii Firmware Version <= 11.04
   CanonMf264dw Ii Version-
CanonMf267dw Ii Firmware Version <= 11.04
   CanonMf267dw Ii Version-
CanonMf269dw Ii Firmware Version <= 11.04
   CanonMf269dw Ii Version-
CanonMf269dw Vp Ii Firmware Version <= 11.04
   CanonMf269dw Vp Ii Version-
CanonMf272dw Firmware Version <= 11.04
   CanonMf272dw Version-
CanonMf273dw Firmware Version <= 11.04
   CanonMf273dw Version-
CanonMf275dw Firmware Version <= 11.04
   CanonMf275dw Version-
CanonMf641cw Firmware Version <= 11.04
   CanonMf641cw Version-
CanonMf746cdw Firmware Version <= 11.04
   CanonMf746cdw Version-
CanonLbp122dw Firmware Version <= 11.04
   CanonLbp122dw Version-
CanonLbp1127c Firmware Version <= 11.04
   CanonLbp1127c Version-
CanonLbp622cdw Firmware Version <= 11.04
   CanonLbp622cdw Version-
CanonLbp623cdw Firmware Version <= 11.04
   CanonLbp623cdw Version-
CanonLbp664cdw Firmware Version <= 11.04
   CanonLbp664cdw Version-
CanonImageprograf Tc-20 Firmware Version <= 11.04
   CanonImageprograf Tc-20 Version-
CanonImageprograf Tc-20m Firmware Version <= 11.04
   CanonImageprograf Tc-20m Version-
CanonPixma G3270 Firmware Version <= 11.04
   CanonPixma G3270 Version-
CanonPixma G4270 Firmware Version <= 11.04
   CanonPixma G4270 Version-
CanonMaxify Gx3020 Firmware Version <= 11.04
   CanonMaxify Gx3020 Version-
CanonMaxify Gx4020 Firmware Version <= 11.04
   CanonMaxify Gx4020 Version-
CanonI-sensys Lbp621cw Firmware Version <= 11.04
   CanonI-sensys Lbp621cw Version-
CanonI-sensys Lbp623cdw Firmware Version <= 11.04
   CanonI-sensys Lbp623cdw Version-
CanonI-sensys Lbp633cdw Firmware Version <= 11.04
   CanonI-sensys Lbp633cdw Version-
CanonI-sensys Lbp664cx Firmware Version <= 11.04
   CanonI-sensys Lbp664cx Version-
CanonI-sensys Mf641cw Firmware Version <= 11.04
   CanonI-sensys Mf641cw Version-
CanonI-sensys Mf643cdw Firmware Version <= 11.04
   CanonI-sensys Mf643cdw Version-
CanonI-sensys Mf645cx Firmware Version <= 11.04
   CanonI-sensys Mf645cx Version-
CanonI-sensys Mf742cdw Firmware Version <= 11.04
   CanonI-sensys Mf742cdw Version-
CanonI-sensys Mf744cdw Firmware Version <= 11.04
   CanonI-sensys Mf744cdw Version-
CanonI-sensys Mf746cx Firmware Version <= 11.04
   CanonI-sensys Mf746cx Version-
CanonI-sensys X C1127i Firmware Version <= 11.04
   CanonI-sensys X C1127i Version-
CanonI-sensys X C1127if Firmware Version <= 11.04
   CanonI-sensys X C1127if Version-
CanonI-sensys X C1127p Firmware Version <= 11.04
   CanonI-sensys X C1127p Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.128
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
f98c90f0-e9bd-4fa7-911b-51993f3571fd 2.2 0.7 1.4
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
CWE-1285 Improper Validation of Specified Index, Position, or Offset in Input

The product receives input that is expected to specify an index, position, or offset into an indexable resource such as a buffer or file, but it does not validate or incorrectly validates that the specified index/position/offset has the required properties.