CVE-2022-26320
Severity CVSS v4.0:
Pending analysis
Type:
CWE-330
Use of Insufficiently Random Value
Publication date:
14/03/2022
Last modified:
07/10/2024
Description
The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with Fermat's factorization method. This allows efficient calculation of private RSA keys from the public key of a TLS certificate.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Base Score 2.0
6.40
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:rambus:safezone_basic_crypto_module:*:*:*:*:non-fips_certified:*:*:* | 9.3.0 (including) | 10.4.0 (excluding) |
| cpe:2.3:o:fujifilm:apeos_c7070_firmware:*:*:*:*:*:*:*:* | 1.1.7 (excluding) | |
| cpe:2.3:h:fujifilm:apeos_c7070:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fujifilm:apeos_c6570_firmware:*:*:*:*:*:*:*:* | 1.1.7 (excluding) | |
| cpe:2.3:h:fujifilm:apeos_c6570:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fujifilm:apeos_c5570_firmware:*:*:*:*:*:*:*:* | 1.1.7 (excluding) | |
| cpe:2.3:h:fujifilm:apeos_c5570:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fujifilm:apeos_c4570_firmware:*:*:*:*:*:*:*:* | 1.1.7 (excluding) | |
| cpe:2.3:h:fujifilm:apeos_c4570:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fujifilm:apeos_c3570_firmware:*:*:*:*:*:*:*:* | 1.1.7 (excluding) | |
| cpe:2.3:h:fujifilm:apeos_c3570:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fujifilm:apeos_c3070_firmware:*:*:*:*:*:*:*:* | 1.1.7 (excluding) | |
| cpe:2.3:h:fujifilm:apeos_c3070:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fujifilm:apeos_c7070_g_firmware:*:*:*:*:*:*:*:* | 1.1.7 (excluding) | |
| cpe:2.3:h:fujifilm:apeos_c7070_g:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://fermatattack.secvuln.info
- https://global.canon/en/support/security/index.html
- https://web.archive.org/web/20220922042721/https://safezoneswupdate.com/
- https://www.fujifilm.com/fbglobal/eng/company/news/notice/2022/0302_rsakey_announce.html
- https://www.rambus.com/security/response-center/advisories/rmbs-2021-01/



