cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

CP2025-005 - Are Canon Generic drivers affected or only Canon Generic Plus?

bjoel
Apprentice

Hello - 

I've been in the process of updating our Canon Generic Plus PCL6, Canon Generic Plus PS3, and Canon Generic Plus UFR II across our printing infrastructure to remediate the CVE's contained in CP2025-005 (CVE-2025-7698, CVE-2025-9903, CVE-2025-9904). We also utilize the Canon Generic PCL6 & Canon Generic PS3 drivers for some devices and found that installing v3.40 of the "Generic Plus" drivers wiped DEVMODE settings on the print queues using the "Generic" driver version. Are these drivers also affected by the CVEs, and if so where can we get the updated versions or is the recommendation to move everything to the "Generic Plus" drivers since these since they don't seem available any longer?

Thanks in advance.

3 REPLIES 3

ellie
Moderator
Moderator

Thanks for posting!

While Canon Community members are welcome to chime in, your authorized Canon dealer remains your primary contact for support for imageRUNNER series products.

If you’re unsure of your dealer or need assistance finding one, please call us at 800-OK-CANON (+1-800-652-2666), and we’ll help connect you with the right resources.

bjoel
Apprentice

Hi Ellie - 

We provide hosted application and print-server infrastructure for healthcare organizations. We operate Windows print servers containing Canon print queues required by the EMR application, but we do not purchase, own, install, or maintain the physical Canon printers. Those devices are owned and supported independently by each hospital system.

Because we only host the server-side print queues and deploy Canon’s driver software, we do not have an authorized Canon dealer associated with these printers. Our question concerns the Canon driver itself, specifically whether the Canon Generic PCL6 driver is distinct from, or affected by the same vulnerability as, the Canon Generic Plus PCL6 driver. We need Canon product or security engineering to clarify the affected driver scope; this isn’t a physical printer service request.

Hi bjoel,

Thank you for providing that additional context regarding your hosted server infrastructure. To be clear, these printers, their software, and drivers are not supported in the Canon Community.

To address your questions regarding security advisory CP2025-005:

  1. Driver Scope: The advisory covers legacy PCL drivers under the PCL Printer Driver (V15.00 and earlier) designation, which includes legacy Generic PCL6 driver releases. Updated versions (V15.01 and higher) address the identified CVEs (CVE-2025-7698, CVE-2025-9903, CVE-2025-9904).
  2. Architecture & DEVMODE: Because legacy Generic drivers and Generic Plus drivers utilize different core code architectures, upgrading existing queues directly from Generic to Generic Plus will cause DEVMODE configuration settings to reset.
Software Authorization & Next Steps:
  • Licensing & Authorization: Canon enterprise drivers and maintenance releases are licensed software made available exclusively through authorized sales representatives and dealer networks under specific device service agreements. As a third-party hosting provider, hosting or deploying unmanaged Canon software builds may fall outside standard licensing terms.
  • Coordination via Client IT: The appropriate path forward is to have your healthcare clients' IT departments contact their assigned authorized Canon dealer or account team. Their dealers can supply the updated, licensed driver packages (such as PCL Printer Driver V15.01+ or Generic Plus V3.31+) and work with you on an approved deployment strategy to preserve queue configurations.
  • Security Reporting: If your technical/compliance team requires direct product security validation beyond dealer channels, you may submit a formal request via the Canon PSIRT Vulnerability Reporting Form.
Announcements