Thank you for your continued trust in Canon products. We have identified a Passback vulnerability in certain Office / Small Office Multifunction Printers and Laser Printers. If malicious actors gain administrative rights, they can obtain authentication information for SMTP / LDAP connections found on the products.
Affected Products/Versions
- imageCLASS LBP Series
- imageCLASS MF Series
- imageCLASS X Series
- imagePRESS Series
- imagePRESS V Series
- imageRUNNER Series
- imageRUNNER C Series
- imageRUNNER ADVANCE Series
Please see below for the list of applicable products.
Mitigation
We recommend the following measures:
- Network Configuration: Avoid connecting the product directly to internet. Use a private IP address on a secure private network with firewalls, wired or Wi-Fi routers.
- Password Management: Change the product’s default password to a stronger password.
- User Accounts: Create distinct administrator, general user IDs and passwords.
- Password Complexity: Ensure passwords and other similar settings are difficult to decipher.
- Multi-Factor Authentication: Enable multi-factor authentication (if available) to verify the identities of end-users.
For more information on how to secure your product on network connections, refer to Hardening Guide.
In addition to implementing the abovementioned measures, to ensure safer usage, newer products have been upgraded with advanced security features. (Please see below for the list of applicable products)
Subscribers to our eMaintenance service will receive software updates automatically for these products with enhanced security features. If you do not have a subscription and require these updates, contact your local Canon service representative.
First Posted on 20 May 2025