Buffer overflow in XPS data font processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw firmware v05.04 and earlier sold in Japan. Color imageCLASS MF656Cdw/Color imageCLASS MF654Cdw/Color imageCLASS MF653Cdw/Color imageCLASS MF652Cdw/Color imageCLASS LBP633Cdw/Color imageCLASS LBP632Cdw firmware v05.04 and earlier sold in US. i-SENSYS MF657Cdw/i-SENSYS MF655Cdw/i-SENSYS MF651Cdw/i-SENSYS LBP633Cdw/i-SENSYS LBP631Cdw firmware v05.04 and earlier sold in Europe.
Conclusion & alert: CVE-2024-12649 is rated Moderate Risk (58/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 0.31%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-10 | 0.24% | 0.31% | +0.07% |
| 2 | 2026-03-08 | 0.44% | 0.24% | -0.20% |
| 3 | 2026-01-27 | — | 0.44% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | f98c90f0-e9bd-4fa7-911b-51993f3571fd |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| canon | mf455dw_firmware | <= 05.04 | cpe:2.3:o:canon:mf455dw_firmware:*:*:*:*:*:*:*:* |
| canon | mf453dw_firmware | <= 05.04 | cpe:2.3:o:canon:mf453dw_firmware:*:*:*:*:*:*:*:* |
| canon | mf452dw_firmware | <= 05.04 | cpe:2.3:o:canon:mf452dw_firmware:*:*:*:*:*:*:*:* |
| canon | mf451dw_firmware | <= 05.04 | cpe:2.3:o:canon:mf451dw_firmware:*:*:*:*:*:*:*:* |
| canon | mf465dw_firmware | <= 05.04 | cpe:2.3:o:canon:mf465dw_firmware:*:*:*:*:*:*:*:* |
| canon | mf462dw_firmware | <= 05.04 | cpe:2.3:o:canon:mf462dw_firmware:*:*:*:*:*:*:*:* |
| canon | mf656cdw_firmware | <= 05.04 | cpe:2.3:o:canon:mf656cdw_firmware:*:*:*:*:*:*:*:* |
| canon | mf654cdw_firmware | <= 05.04 | cpe:2.3:o:canon:mf654cdw_firmware:*:*:*:*:*:*:*:* |
| canon | mf653cdw_firmware | <= 05.04 | cpe:2.3:o:canon:mf653cdw_firmware:*:*:*:*:*:*:*:* |
| canon | mf652cw_firmware | <= 05.04 | cpe:2.3:o:canon:mf652cw_firmware:*:*:*:*:*:*:*:* |
| canon | mf1238_ii_firmware | <= 05.04 | cpe:2.3:o:canon:mf1238_ii_firmware:*:*:*:*:*:*:*:* |
| canon | mf1440_firmware | <= 05.04 | cpe:2.3:o:canon:mf1440_firmware:*:*:*:*:*:*:*:* |
| canon | mf1643if_ii_firmware | <= 05.04 | cpe:2.3:o:canon:mf1643if_ii_firmware:*:*:*:*:*:*:*:* |
| canon | mf1643i_ii_firmware | <= 05.04 | cpe:2.3:o:canon:mf1643i_ii_firmware:*:*:*:*:*:*:*:* |
| canon | lbp237dw_firmware | <= 05.04 | cpe:2.3:o:canon:lbp237dw_firmware:*:*:*:*:*:*:*:* |
| canon | lbp236dw_firmware | <= 05.04 | cpe:2.3:o:canon:lbp236dw_firmware:*:*:*:*:*:*:*:* |
| canon | lbp247dw_firmware | <= 05.04 | cpe:2.3:o:canon:lbp247dw_firmware:*:*:*:*:*:*:*:* |
| canon | lbp246dw_firmware | <= 05.04 | cpe:2.3:o:canon:lbp246dw_firmware:*:*:*:*:*:*:*:* |
| canon | lbp633cdw_firmware | <= 05.04 | cpe:2.3:o:canon:lbp633cdw_firmware:*:*:*:*:*:*:*:* |
| canon | lbp632cdw_firmware | <= 05.04 | cpe:2.3:o:canon:lbp632cdw_firmware:*:*:*:*:*:*:*:* |
| canon | lbp1238_ii_firmware | <= 05.04 | cpe:2.3:o:canon:lbp1238_ii_firmware:*:*:*:*:*:*:*:* |
| canon | lbp1440_firmware | <= 05.04 | cpe:2.3:o:canon:lbp1440_firmware:*:*:*:*:*:*:*:* |