关键信息 漏洞概述 漏洞编号: JVNVU#93897456 漏洞类型: Out-of-bounds write vulnerability 受影响产品: FUJIFILM Business Innovation MFPs (多功能打印机) 受影响的产品 DocuPrint CP225 w 01.23.02 and earlier DocuPrint CP228 w 01.23.02 and earlier DocuPrint CP115 w 01.09.00 and earlier DocuPrint CP118 w 01.09.00 and earlier DocuPrint CP116 w 01.09.00 and earlier DocuPrint CP119 w 01.09.00 and earlier DocuPrint CM225 fw 01.12.02 and earlier DocuPrint CM228 fw 01.12.02 and earlier DocuPrint CM115 w 01.09.01 and earlier DocuPrint CM118 w 01.09.01 and earlier Apeos 2150 N 01.00.47 and earlier Apeos 2350 NDA 01.00.47 and earlier Apeos 2150 ND 01.00.47 and earlier Apeos 2150 NDA 01.00.47 and earlier 描述 漏洞详情: Out-of-bounds Write (CWE-787) CVSS评分: - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Base Score 6.9 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Base Score 5.3 CVE编号: CVE-2025-48499 影响 特殊构造的IPP或LPD数据包可能导致受影响的MFP出现拒绝服务(DoS)条件,需要重置MFP才能恢复。 解决方案 更新固件: 根据开发人员提供的信息应用适当的固件更新。 报告者 Jia-Ju Bai, Rui-Nan Hu, Dong Zhang, 和 Zhen-Yu Guan of School of Cyber Science and Technology of Beihang University报告了此漏洞。