V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2023-0852
CVE
Critical

Buffer overflow in the Address Book of Mobile Device function of Office / Small Office Multifunction Printers and Laser Printers(*) which m…

CVSS
9.8
Critical
EPSS
0.01
p62
Published
2023-01-01
Updated
2023-01-01
Description

Buffer overflow in the Address Book of Mobile Device function of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier sold in US. i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF, C1127i firmware Ver.11.04 and earlier sold in Europe.

Tags · CWE
Pre-auth
CWE-121
Affected products
I-sensys_lbp621cw_firmwareI-sensys_lbp623cdw_firmwareI-sensys_lbp633cdw_firmwareI-sensys_lbp664cx_firmwareI-sensys_mf641cw_firmwareI-sensys_mf643cdw_firmwareI-sensys_mf645cx_firmwareI-sensys_mf742cdw_firmwareI-sensys_mf744cdw_firmwareI-sensys_mf746cx_firmwareI-sensys_x_c1127i_firmwareI-sensys_x_c1127if_firmwareI-sensys_x_c1127p_firmwareImageprograf_tc-20_firmwareImageprograf_tc-20m_firmwareLbp1127c_firmwareLbp122dw_firmwareLbp621c_firmwareLbp622c_firmwareLbp622cdw_firmware
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2023-01-01
Published
2023-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.011 · p62
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
i-sensys_lbp621cw_firmware*Tracked
i-sensys_lbp623cdw_firmware*Tracked
i-sensys_lbp633cdw_firmware*Tracked
i-sensys_lbp664cx_firmware*Tracked
i-sensys_mf641cw_firmware*Tracked
i-sensys_mf643cdw_firmware*Tracked
i-sensys_mf645cx_firmware*Tracked
i-sensys_mf742cdw_firmware*Tracked
i-sensys_mf744cdw_firmware*Tracked
i-sensys_mf746cx_firmware*Tracked
i-sensys_x_c1127i_firmware*Tracked
i-sensys_x_c1127if_firmware*Tracked
i-sensys_x_c1127p_firmware*Tracked
imageprograf_tc-20_firmware*Tracked
imageprograf_tc-20m_firmware*Tracked
lbp1127c_firmware*Tracked
lbp122dw_firmware*Tracked
lbp621c_firmware*Tracked
lbp622c_firmware*Tracked
lbp622cdw_firmware*Tracked
Showing first 20 of 45
Source databases
CVE
Related vulnerabilities