CERT-In Vulnerability Note
CIVN-2021-0379
Multiple Vulnerabilities in Konica Minolta printers
Original Issue Date:December 31, 2021
Severity Rating: HIGH
Software Affected
- bizhub C750i printer version G00-35 or prior to
- bizhub C650i/C550i/C450i printer version G00-B6 or prior to
- bizhub C360i/C300i/C250i printer version G00-B6 or prior to
- bizhub 750i/650i/550i/450i printer version G00-37 or prior to
- bizhub 360i/300i printer version G00-33 or prior to
- bizhub C287i/C257i/C227i printer version G00-19 or prior to
- bizhub 306i/266i/246i/226i printer version G00-B6 or prior to
- bizhub C759/C659/ C658/C558/C458/ 958/808/758/ 658e/558e/458e printer version GC7-X8 or prior to
- bizhub C287/C227/ 287/227 printer version GC7-X8 or prior to
- bizhub 368e/308e printer version GC7-X8 or prior to
- bizhub C368/C308/C258 printer version GC9-X4 or prior to
- bizhub C754e/C654e/ 754e/654e printer version GDQ-M0 or prior to
- bizhub C554e/C454e/ C364e/C284e/C224e printer version GDQ-M1 or prior to
- bizhub 554e/454e/364e/284e/224e printer version GDQ-M1 or prior to
- bizhub C754/C654, C554/C454/ C364/C284/C224/ 754/654 printer version GR1-M0 or prior to
- bizhub C4050i/C3350i/C4000i/C3300i/ C3320i printer version G00-B6 or prior to
- bizhub 4750i/4050i/ 4700i printer version G00-22 or prior to
- bizhub C3851FS/C3851/C3351/ 4752/4052 printer version GC9-X4 or prior to
- bizhub C3850/C3350/3850FS/ 4750/4050/ C3110/ C3100P printers.
Overview
Multiple Vulnerabilities have been reported in Konica Minolta multifunction printers and single-function printers which could allow a local or remote attacker to obtain sensitive information and bypass security restrictions on the targeted system.
Description
1. Security Restriction Bypass Vulnerability
(
CVE-2021-20868
CVE-2021-20872
)
These vulnerabilities exists in Konica Minolta multifunction printers and single-function printers due to incorrect authorization and failure of firmware integrity verification that exists on the device that could allow the attacker to bypass security restrictions. An attacker could exploit these vulnerabilities by using a SOAP message or installing malicious firmware. Successful exploitation of these vulnerabilities could allow the attacker to steal user credentials with administrative privileges of the targeted device.
2. Information Disclosure Vulnerability
(
CVE-2021-20869
CVE-2021-20870
CVE-2021-20871
)
These vulnerabilities exists in Konica Minolta multifunction printers and single-function printers due to an error in LDAP server authentication, improper handling of exceptional conditions and including credentials in the destination address book that could allow a remote attacker to obtain sensitive information of the affected device. An attacker could exploit these vulnerabilities by using SOAP messages or ejecting a HDD before the scan job times out. Successful exploitation of these vulnerabilities could allow the attacker to steal registered authentication information of the affected device.
Solution
Apply appropriate updates as mentioned in:
https://www.konicaminolta.com/global/newsroom/topics/2021/1224-01-01.html
Vendor Information
KONICA MINOLTA
https://www.konicaminolta.com/global/newsroom/topics/2021/1224-01-01.html
References
KONICA MINOLTA
https://www.konicaminolta.com/global/newsroom/topics/2021/1224-01-01.html
CVE Name
CVE-2021-20868
CVE-2021-20872
CVE-2021-20869
CVE-2021-20870
CVE-2021-20871
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|