🛡️ CVE-2022-24674
🟠 CVSS 8.8 — High ✅ No Known Exploit CWE-121 NVD
8.8
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the privet API. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15834.

Details

Severity HIGH
CVSS Score 8.8
CVSS Vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE CWE-121
Public Exploit ✅ No
Source NVD
Published 2023-03-28
Updated 2026-06-08
Modified 2024-11-21
Fix URL N/A

Affected Packages

Software From version Fixed in
1435i\+-firmware
1435if-firmware
1435if\+-firmware
1435p-firmware
1435p\+-firmware
d1520-firmware
d1550-firmware
d1620-firmware
d1650-firmware
ir1435i-firmware
ir1643i-firmware
ir1643if-firmware
lbp1127c-firmware
lbp1238-firmware
lbp1238-ii-firmware
lbp214dw-firmware
lbp215dw-firmware
lbp226dw-firmware
lbp227dw-firmware
lbp228dw-firmware
lbp236dw-firmware
lbp237dw-firmware
lbp251dw-firmware
lbp253dw-firmware
lbp612cdw-firmware
lbp622cdw-firmware
lbp623cdw-firmware
lbp654cdw-firmware
lbp664cdw-firmware
mf1127c-firmware
mf1238-firmware
mf1238-ii-firmware
mf1643i-ii-firmware
mf1643if-ii-firmware
mf414dw-firmware
mf416dw-firmware
mf419dw-firmware
mf424dw-firmware
mf426dw-firmware
mf429dw-firmware
mf445dw-firmware
mf448dw-firmware
mf449dw-firmware
mf451dw-firmware
mf452dw-firmware
mf453dw-firmware
mf455dw-firmware
mf515dw-firmware
mf525dw-firmware
mf543dw-firmware
mf6160dw-firmware
mf6180dw-firmware
mf624cdw-firmware
mf628cdw-firmware
mf632cdw-firmware
mf634cdw-firmware
mf641cw-firmware
mf642cdw-firmware
mf644cdw-firmware
mf726cdw-firmware
mf729cdw-firmware
mf731cdw-firmware
mf733cdw-firmware
mf735cdw-firmware
mf741cdw-firmware
mf743cdw-firmware
mf745cdw-firmware
mf746cdw-firmware
mf810cdn-firmware
mf820cdn-firmware
mf8280cw-firmware
mf8580cdw-firmware
wg7240-firmware
wg7250-firmware
wg7250f-firmware
wg7250z-firmware

Exploit Protection

Help block exploit attempts

BotEraser is designed to detect and help reduce malicious bot traffic that may target known vulnerabilities on your site.

Try BotEraser Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.