CVE-2023-46327

MEDIUMCVSS 5.9/10EPSS 0.35%

Last modified

CVE-2023-46327 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a facility to export the contents of their Address Book with encrypted form, but the encryption strength is insufficient. EPSS estimates a 0.35% chance of exploitation in the next 30 days.

Description

Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a facility to export the contents of their Address Book with encrypted form, but the encryption strength is insufficient. With the knowledge of the encryption process and the encryption key, the information such as the server credentials may be obtained from the exported Address Book data. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

Metrics

CVSS 3.1
5.9/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
0.35%

26.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
XeroxPrimelink C9065 Firmware< 85.40.31
XeroxPrimelink C9070 Firmware< 85.40.31
XeroxPrimelink B9136 Firmware< 90.40.91
XeroxPrimelink B9125 Firmware< 90.40.91
XeroxPrimelink B9110 Firmware< 90.40.91
XeroxPrimelink B9100 Firmware< 90.40.91
XeroxVersalink C405 Firmware< 68.81.41
XeroxVersalink C505 Firmware< 68.81.41
XeroxVersalink C605 Firmware< 68.81.41
XeroxVersalink C7000 Firmware< 56.74.51
XeroxVersalink C7020 Firmware< 57.74.51
XeroxVersalink C7025 Firmware< 57.74.51
XeroxVersalink C7030 Firmware< 57.74.51
XeroxVersalink C7130 Firmware< 69.23.41
XeroxVersalink C7125 Firmware< 69.23.41
XeroxVersalink C7120 Firmware< 69.23.41
XeroxVersalink B405 Firmware< 38.81.41
XeroxVersalink B605 Firmware< 38.81.41
XeroxVersalink B615 Firmware< 38.81.41
XeroxVersalink B7125 Firmware< 59.23.41
XeroxVersalink B7130 Firmware< 59.23.41
XeroxVersalink B7135 Firmware< 59.23.41
XeroxWorkcentre 6515 Firmware< 65.74.51
FujifilmApeos 3560 Firmware>= 1.0.0, <= 1.2.16
FujifilmApeos 3560 Firmware>= 1.20.0, <= 1.26.10
FujifilmApeos 3060 Firmware>= 1.0.0, <= 1.2.16
FujifilmApeos 3060 Firmware>= 1.20.0, <= 1.26.10
FujifilmApeos 2560 Firmware>= 1.0.0, <= 1.2.16
FujifilmApeos 2560 Firmware>= 1.20.0, <= 1.26.10
FujifilmApeos 3560 Gk Firmware>= 1.0.0, <= 1.2.16
FujifilmApeos 3560 Gk Firmware>= 1.20.0, <= 1.26.10
FujifilmApeos 3060 Gk Firmware>= 1.0.0, <= 1.2.16
FujifilmApeos 3060 Gk Firmware>= 1.20.0, <= 1.26.10
FujifilmApeos 2560 Gk Firmware>= 1.0.0, <= 1.2.16
FujifilmApeos 2560 Gk Firmware>= 1.20.0, <= 1.26.10
FujifilmApeos 5330 Firmware< 1.20.9
FujifilmApeos 4830 Firmware< 1.20.9
FujifilmApeos 5570 Firmware>= 1.0.0, <= 1.3.6
FujifilmApeos 5570 Firmware>= 1.21.0, <= 1.26.9
FujifilmApeos 4570 Firmware>= 1.0.0, <= 1.3.6
FujifilmApeos 4570 Firmware>= 1.21.0, <= 1.26.9
FujifilmApeos 6340 Firmware>= 1.0.0, <= 1.2.11
FujifilmApeos 6340 Firmware>= 1.20.0, <= 1.20.6
FujifilmApeos 7580 Firmware< 1.26.9
FujifilmApeos 6580 Firmware< 1.26.9
FujifilmApeos C2570 Firmware>= 1.0.0, <= 1.3.7
FujifilmApeos C2570 Firmware>= 1.21.0, <= 1.26.11
FujifilmApeos C3070 Firmware>= 1.0.0, <= 1.3.7
FujifilmApeos C3070 Firmware>= 1.21.0, <= 1.26.11
FujifilmApeos C3570 Firmware>= 1.0.0, <= 1.3.7

Showing 50 of 130 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-46327?
Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a facility to export the contents of their Address Book with encrypted form, but the encryption strength is insufficient. With the knowledge of the encryption process and the encryption key, the information such as the server credentials may be obtained from the exported Address Book data. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
How severe is CVE-2023-46327?
CVE-2023-46327 has a CVSS score of 5.9/10 (MEDIUM severity). The EPSS model estimates a 0.35% probability of exploitation in the next 30 days.
How do I fix CVE-2023-46327?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-46327?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST