Published:2025/02/17  Last Updated:2025/02/17

JVNVU#96297631
Out-of-bounds write vulnerability in FUJIFILM Business Innovation Corp. MFPs

Overview

Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. contain an out-of-bounds write vulnerability.

Products Affected

  • DocuPrint CP225w 01.22.01 and earlier
  • DocuPrint CP228w 01.22.01 and earlier
  • DocuPrint CM225fw 01.10.01 and earlier
  • DocuPrint CM228fw 01.10.01 and earlier

Description

Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. contain an out-of-bounds vulnerability (CWE-787, CVE-2024-45320) due to a flaw in verifying the length of data.

Impact

If an affected MFP processes a specially crafted printer job file, a denial-of-service (DoS) condition may occur.
Resetting the MFP is required to recover from the denial-of-service (DoS) condition.

Solution

Update the firmware
Apply the appropriate firmware update according to the information provided by the developer.

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

CVSS v3 CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score: 6.5
Attack Vector(AV) Physical (P) Local (L) Adjacent (A) Network (N)
Attack Complexity(AC) High (H) Low (L)
Privileges Required(PR) High (H) Low (L) None (N)
User Interaction(UI) Required (R) None (N)
Scope(S) Unchanged (U) Changed (C)
Confidentiality Impact(C) None (N) Low (L) High (H)
Integrity Impact(I) None (N) Low (L) High (H)
Availability Impact(A) None (N) Low (L) High (H)

Credit

Jia-Ju Bai, Rui-Nan Hu, Cheng Li, Dong Zhang, Yu-Chen Sun, Wen-Han Xu, Zhen-Yu Guan, and Jian-Wei Liu from School of Cyber Science and Technology of Beihang University directly reported this vulnerability to FUJIFILM Business Innovation Corp.
FUJIFILM Business Innovation Corp. reported this case to JPCERT/CC to request the coordination of this case.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2024-45320
JVN iPedia