CVE-2022-26320

Severity CVSS v4.0:
Pending analysis
Type:
CWE-330 Use of Insufficiently Random Value
Publication date:
14/03/2022
Last modified:
07/10/2024

Description

The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with Fermat's factorization method. This allows efficient calculation of private RSA keys from the public key of a TLS certificate.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rambus:safezone_basic_crypto_module:*:*:*:*:non-fips_certified:*:*:* 9.3.0 (including) 10.4.0 (excluding)
cpe:2.3:o:fujifilm:apeos_c7070_firmware:*:*:*:*:*:*:*:* 1.1.7 (excluding)
cpe:2.3:h:fujifilm:apeos_c7070:-:*:*:*:*:*:*:*
cpe:2.3:o:fujifilm:apeos_c6570_firmware:*:*:*:*:*:*:*:* 1.1.7 (excluding)
cpe:2.3:h:fujifilm:apeos_c6570:-:*:*:*:*:*:*:*
cpe:2.3:o:fujifilm:apeos_c5570_firmware:*:*:*:*:*:*:*:* 1.1.7 (excluding)
cpe:2.3:h:fujifilm:apeos_c5570:-:*:*:*:*:*:*:*
cpe:2.3:o:fujifilm:apeos_c4570_firmware:*:*:*:*:*:*:*:* 1.1.7 (excluding)
cpe:2.3:h:fujifilm:apeos_c4570:-:*:*:*:*:*:*:*
cpe:2.3:o:fujifilm:apeos_c3570_firmware:*:*:*:*:*:*:*:* 1.1.7 (excluding)
cpe:2.3:h:fujifilm:apeos_c3570:-:*:*:*:*:*:*:*
cpe:2.3:o:fujifilm:apeos_c3070_firmware:*:*:*:*:*:*:*:* 1.1.7 (excluding)
cpe:2.3:h:fujifilm:apeos_c3070:-:*:*:*:*:*:*:*
cpe:2.3:o:fujifilm:apeos_c7070_g_firmware:*:*:*:*:*:*:*:* 1.1.7 (excluding)
cpe:2.3:h:fujifilm:apeos_c7070_g:-:*:*:*:*:*:*:*