CVE-2022-41807

MEDIUMCVSS 6.5/10EPSS 0.49%

Last modified

CVE-2022-41807 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Missing authorization vulnerability exists in Kyocera Document Solutions MFPs and printers, which may allow a network-adjacent attacker to alter the product settings without authentication by sending a specially crafted request. Affected products/versions are as follows: TASKalfa 7550ci/6550ci, TASKalfa 5550ci/4550ci/3550ci/3050ci, TASKalfa 255c/205c, TASKalfa 256ci/206ci, ECOSYS M6526cdn/M6526cidn, FS-C2126MFP/C2126MFP+/C2026MFP/C2026MFP+, TASKalfa 8000i/6500i, TASKalfa 5500i/4500i/3500i, TASKalfa 305/255, TASKalfa 306i/256i, LS-3140MFP/3140MFP+/3640MFP, ECOSYS M2535dn, LS-1135MFP/1035MFP, LS-C8650DN/C8600DN, ECOSYS P6026cdn, FS-C5250DN, LS-4300DN/4200DN/2100DN, ECOSYS P4040dn, ECOSYS P2135dn, and FS-1370DN.. EPSS estimates a 0.49% chance of exploitation in the next 30 days.

Description

Missing authorization vulnerability exists in Kyocera Document Solutions MFPs and printers, which may allow a network-adjacent attacker to alter the product settings without authentication by sending a specially crafted request. Affected products/versions are as follows: TASKalfa 7550ci/6550ci, TASKalfa 5550ci/4550ci/3550ci/3050ci, TASKalfa 255c/205c, TASKalfa 256ci/206ci, ECOSYS M6526cdn/M6526cidn, FS-C2126MFP/C2126MFP+/C2026MFP/C2026MFP+, TASKalfa 8000i/6500i, TASKalfa 5500i/4500i/3500i, TASKalfa 305/255, TASKalfa 306i/256i, LS-3140MFP/3140MFP+/3640MFP, ECOSYS M2535dn, LS-1135MFP/1035MFP, LS-C8650DN/C8600DN, ECOSYS P6026cdn, FS-C5250DN, LS-4300DN/4200DN/2100DN, ECOSYS P4040dn, ECOSYS P2135dn, and FS-1370DN.

Metrics

CVSS 3.1
6.5/10

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS Probability
0.49%

38.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
KyoceraTaskalfa 7550ci FirmwareAll versions
KyoceraTaskalfa 6550ci FirmwareAll versions
KyoceraTaskalfa 5550ci FirmwareAll versions
KyoceraTaskalfa 4550ci FirmwareAll versions
KyoceraTaskalfa 3550ci FirmwareAll versions
KyoceraTaskalfa 3050ci FirmwareAll versions
KyoceraTaskalfa 255c FirmwareAll versions
KyoceraTaskalfa 205c FirmwareAll versions
KyoceraTaskalfa 256ci FirmwareAll versions
KyoceraTaskalfa 206ci FirmwareAll versions
KyoceraEcosys M6526cdn FirmwareAll versions
KyoceraEcosys M6526cidn FirmwareAll versions
KyoceraFs-C2126mfp FirmwareAll versions
KyoceraFs-C2126mfp\+ FirmwareAll versions
KyoceraFs-C2026mfp FirmwareAll versions
KyoceraTaskalfa 8000i FirmwareAll versions
KyoceraTaskalfa 6500i FirmwareAll versions
KyoceraTaskalfa 5500i FirmwareAll versions
KyoceraTaskalfa 4500i FirmwareAll versions
KyoceraTaskalfa 3500i FirmwareAll versions
KyoceraTaskalfa 305 FirmwareAll versions
KyoceraTaskalfa 255 FirmwareAll versions
KyoceraTaskalfa 306i FirmwareAll versions
KyoceraTaskalfa 256i FirmwareAll versions
KyoceraLs-3140mfp FirmwareAll versions
KyoceraLs-3140mfp\+ FirmwareAll versions
KyoceraLs-3640mfp FirmwareAll versions
KyoceraEcosys M2535dn FirmwareAll versions
KyoceraLs-1135mfp FirmwareAll versions
KyoceraLs-1035mfp FirmwareAll versions
KyoceraLs-C8650dn FirmwareAll versions
KyoceraLs-C8600dn FirmwareAll versions
KyoceraEcosys P6026cdn FirmwareAll versions
KyoceraFs-C5250dn FirmwareAll versions
KyoceraLs-4300dn FirmwareAll versions
KyoceraLs-4200dn FirmwareAll versions
KyoceraLs-2100dn FirmwareAll versions
KyoceraEcosys P4040dn FirmwareAll versions
KyoceraEcosys P2135dn FirmwareAll versions
KyoceraFs-1370dn FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-41807?
Missing authorization vulnerability exists in Kyocera Document Solutions MFPs and printers, which may allow a network-adjacent attacker to alter the product settings without authentication by sending a specially crafted request. Affected products/versions are as follows: TASKalfa 7550ci/6550ci, TASKalfa 5550ci/4550ci/3550ci/3050ci, TASKalfa 255c/205c, TASKalfa 256ci/206ci, ECOSYS M6526cdn/M6526cidn, FS-C2126MFP/C2126MFP+/C2026MFP/C2026MFP+, TASKalfa 8000i/6500i, TASKalfa 5500i/4500i/3500i, TASKalfa 305/255, TASKalfa 306i/256i, LS-3140MFP/3140MFP+/3640MFP, ECOSYS M2535dn, LS-1135MFP/1035MFP, LS-C8650DN/C8600DN, ECOSYS P6026cdn, FS-C5250DN, LS-4300DN/4200DN/2100DN, ECOSYS P4040dn, ECOSYS P2135dn, and FS-1370DN.
How severe is CVE-2022-41807?
CVE-2022-41807 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 0.49% probability of exploitation in the next 30 days.
How do I fix CVE-2022-41807?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-41807?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST