Impact
The vulnerability is an insecure deserialization flaw in Canon PRISMAproduction that allows an attacker to execute arbitrary code. It is identified as CWE-502. A malicious actor can send crafted serialized data to the application and trigger code execution, potentially compromising the device and the wider network.
Affected Systems
Users running Canon PRISMAproduction version 6.5 or earlier are affected. The issue has been reported for all builds up to and including version 6.5; newer versions are presumed to be unaffected unless otherwise noted by Canon.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity, but the EPSS score is not available, so the exploitation likelihood is unclear. The vulnerability is not yet listed in CISA's KEV catalog, suggesting no widespread exploitation has been reported. Attackers would likely deliver the payload over the network by exploiting the deserialization processing, so systems exposed to untrusted input should be considered high risk until a patch is applied.
OpenCVE Enrichment