Lucene search

K
cveJpcertCVE-2021-20872
HistoryJan 04, 2022 - 4:15 a.m.

CVE-2021-20872

2022-01-0404:15:07
jpcert
web.nvd.nist.gov
27
cve-2021-20872
konica minolta
bizhub series
vulnerability
firmware
integrity verification
physical attack

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

6.8

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

51.1%

Protection mechanism failure vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G00-35 and earlier, bizhub C650i/C550i/C450i G00-B6 and earlier, bizhub C360i/C300i/C250i G00-B6 and earlier, bizhub 750i/650i/550i/450i G00-37 and earlier, bizhub 360i/300i G00-33 and earlier, bizhub C287i/C257i/C227i G00-19 and earlier, bizhub 306i/266i/246i/226i G00-B6 and earlier, bizhub C759/C659 GC7-X8 and earlier, bizhub C658/C558/C458 GC7-X8 and earlier, bizhub 958/808/758 GC7-X8 and earlier, bizhub 658e/558e/458e GC7-X8 and earlier, bizhub C287/C227 GC7-X8 and earlier, bizhub 287/227 GC7-X8 and earlier, bizhub 368e/308e GC7-X8 and earlier, bizhub C368/C308/C258 GC9-X4 and earlier, bizhub 558/458/368/308 GC9-X4 and earlier, bizhub C754e/C654e GDQ-M0 and earlier, bizhub 754e/654e GDQ-M0 and earlier, bizhub C554e/C454e GDQ-M1 and earlier, bizhub C364e/C284e/C224e GDQ-M1 and earlier, bizhub 554e/454e/364e/284e/224e GDQ-M1 and earlier, bizhub C754/C654 C554/C454 GR1-M0 and earlier, bizhub C364/C284/C224 GR1-M0 and earlier, bizhub 754/654 GR1-M0 and earlier, bizhub C3851FS/C3851/C3351 GC9-X4 and earlier, bizhub 4752/4052 GC9-X4 and earlier) allows a physical attacker to bypass the firmware integrity verification and to install malicious firmware.

Affected configurations

Nvd
Node
konicaminoltabizhub_c759_firmwareRange<gca-y1
AND
konicaminoltabizhub_c759Match-
Node
konicaminoltabizhub_c659_firmwareRange<gca-y1
AND
konicaminoltabizhub_c659Match-
Node
konicaminoltabizhub_c658_firmwareRange<gca-y1
AND
konicaminoltabizhub_c658Match-
Node
konicaminoltabizhub_c558_firmwareRange<gca-y1
AND
konicaminoltabizhub_c558Match-
Node
konicaminoltabizhub_c458_firmwareRange<gca-y1
AND
konicaminoltabizhub_c458Match-
Node
konicaminoltabizhub_958_firmwareRange<gca-y1
AND
konicaminoltabizhub_958Match-
Node
konicaminoltabizhub_808_firmwareRange<gca-y1
AND
konicaminoltabizhub_808Match-
Node
konicaminoltabizhub_758_firmwareRange<gca-y1
AND
konicaminoltabizhub_758Match-
Node
konicaminoltabizhub_658e_firmwareRange<gca-y1
AND
konicaminoltabizhub_658eMatch-
Node
konicaminoltabizhub_558e_firmwareRange<gca-y1
AND
konicaminoltabizhub_558eMatch-
Node
konicaminoltabizhub_458e_firmwareRange<gca-y1
AND
konicaminoltabizhub_458eMatch-
Node
konicaminoltabizhub_c287_firmwareRange<gca-y0
AND
konicaminoltabizhub_c287Match-
Node
konicaminoltabizhub_c227_firmwareRange<gca-y0
AND
konicaminoltabizhub_c227Match-
Node
konicaminoltabizhub_287_firmwareRange<gca-y0
AND
konicaminoltabizhub_287Match-
Node
konicaminoltabizhub_227_firmwareRange<gca-y0
AND
konicaminoltabizhub_227Match-
Node
konicaminoltabizhub_368e_firmwareRange<gca-x8
AND
konicaminoltabizhub_368eMatch-
Node
konicaminoltabizhub_308e_firmwareRange<gca-x8
AND
konicaminoltabizhub_308eMatch-
Node
konicaminoltabizhub_c368_firmwareRange<gca-x4
AND
konicaminoltabizhub_c368Match-
Node
konicaminoltabizhub_c308_firmwareRange<gca-x4
AND
konicaminoltabizhub_c308Match-
Node
konicaminoltabizhub_c258_firmwareRange<gca-x4
AND
konicaminoltabizhub_c258Match-
Node
konicaminoltabizhub_558_firmwareRange<gca-x4
AND
konicaminoltabizhub_558Match-
Node
konicaminoltabizhub_458_firmwareRange<gca-x4
AND
konicaminoltabizhub_458Match-
Node
konicaminoltabizhub_368_firmwareRange<gca-x4
AND
konicaminoltabizhub_368Match-
Node
konicaminoltabizhub_308_firmwareRange<gca-x4
AND
konicaminoltabizhub_308Match-
Node
konicaminoltabizhub_c754e_firmwareRange<gdr-m0
AND
konicaminoltabizhub_c754eMatch-
Node
konicaminoltabizhub_c654e_firmwareRange<gdr-m0
AND
konicaminoltabizhub_c654eMatch-
Node
konicaminoltabizhub_754e_firmwareRange<gdr-m0
AND
konicaminoltabizhub_754eMatch-
Node
konicaminoltabizhub_654e_firmwareRange<gdr-m0
AND
konicaminoltabizhub_654eMatch-
Node
konicaminoltabizhub_c554e_firmwareRange<gdr-m1
AND
konicaminoltabizhub_c554eMatch-
Node
konicaminoltabizhub_c454e_firmwareRange<gdr-m1
AND
konicaminoltabizhub_c454eMatch-
Node
konicaminoltabizhub_c364e_firmwareRange<gdr-m1
AND
konicaminoltabizhub_c364eMatch-
Node
konicaminoltabizhub_c284e_firmwareRange<gdr-m1
AND
konicaminoltabizhub_c284eMatch-
Node
konicaminoltabizhub_c224e_firmwareRange<gdr-m1
AND
konicaminoltabizhub_c224eMatch-
Node
konicaminoltabizhub_554e_firmwareRange<gdr-m1
AND
konicaminoltabizhub_554eMatch-
Node
konicaminoltabizhub_454e_firmwareRange<gdr-m1
AND
konicaminoltabizhub_454eMatch-
Node
konicaminoltabizhub_364e_firmwareRange<gdr-m1
AND
konicaminoltabizhub_364eMatch-
Node
konicaminoltabizhub_284e_firmwareRange<gdr-m1
AND
konicaminoltabizhub_284eMatch-
Node
konicaminoltabizhub_224e_firmwareRange<gdr-m1
AND
konicaminoltabizhub_224eMatch-
Node
konicaminoltabizhub_c754_firmwareRange<gr4-m0
AND
konicaminoltabizhub_c754Match-
Node
konicaminoltabizhub_c654_firmwareRange<gr4-m0
AND
konicaminoltabizhub_c654Match-
Node
konicaminoltabizhub_c554_firmwareRange<gr4-m0
AND
konicaminoltabizhub_c554Match-
Node
konicaminoltabizhub_c454_firmwareRange<gr4-m0
AND
konicaminoltabizhub_c454Match-
Node
konicaminoltabizhub_c364_firmwareRange<gr4-m0
AND
konicaminoltabizhub_c364Match-
Node
konicaminoltabizhub_c284_firmwareRange<gr4-m0
AND
konicaminoltabizhub_c284Match-
Node
konicaminoltabizhub_c224_firmwareRange<gr4-m0
AND
konicaminoltabizhub_c224Match-
Node
konicaminoltabizhub_754_firmwareRange<gr4-m0
AND
konicaminoltabizhub_754Match-
Node
konicaminoltabizhub_654_firmwareRange<gr4-m0
AND
konicaminoltabizhub_654Match-
Node
konicaminoltabizhub_c3851fs_firmwareRange<gca-x4
AND
konicaminoltabizhub_c3851fsMatch-
Node
konicaminoltabizhub_c3851_firmwareRange<gca-x4
AND
konicaminoltabizhub_c3851Match-
Node
konicaminoltabizhub_c3351_firmwareRange<gca-x4
AND
konicaminoltabizhub_c3351Match-
Node
konicaminoltabizhub_4752_firmwareRange<gca-x4
AND
konicaminoltabizhub_4752Match-
Node
konicaminoltabizhub_4052_firmwareRange<gca-x4
AND
konicaminoltabizhub_4052Match-
VendorProductVersionCPE
konicaminoltabizhub_c759_firmware*cpe:2.3:o:konicaminolta:bizhub_c759_firmware:*:*:*:*:*:*:*:*
konicaminoltabizhub_c759-cpe:2.3:h:konicaminolta:bizhub_c759:-:*:*:*:*:*:*:*
konicaminoltabizhub_c659_firmware*cpe:2.3:o:konicaminolta:bizhub_c659_firmware:*:*:*:*:*:*:*:*
konicaminoltabizhub_c659-cpe:2.3:h:konicaminolta:bizhub_c659:-:*:*:*:*:*:*:*
konicaminoltabizhub_c658_firmware*cpe:2.3:o:konicaminolta:bizhub_c658_firmware:*:*:*:*:*:*:*:*
konicaminoltabizhub_c658-cpe:2.3:h:konicaminolta:bizhub_c658:-:*:*:*:*:*:*:*
konicaminoltabizhub_c558_firmware*cpe:2.3:o:konicaminolta:bizhub_c558_firmware:*:*:*:*:*:*:*:*
konicaminoltabizhub_c558-cpe:2.3:h:konicaminolta:bizhub_c558:-:*:*:*:*:*:*:*
konicaminoltabizhub_c458_firmware*cpe:2.3:o:konicaminolta:bizhub_c458_firmware:*:*:*:*:*:*:*:*
konicaminoltabizhub_c458-cpe:2.3:h:konicaminolta:bizhub_c458:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 1041

CNA Affected

[
  {
    "product": "bizhub series",
    "vendor": "KONICA MINOLTA, INC.",
    "versions": [
      {
        "status": "affected",
        "version": "bizhub C750i G00-35 and earlier, bizhub C650i/C550i/C450i G00-B6 and earlier, bizhub C360i/C300i/C250i G00-B6 and earlier, bizhub 750i/650i/550i/450i G00-37 and earlier, bizhub 360i/300i G00-33 and earlier, bizhub C287i/C257i/C227i G00-19 and earlier, bizhub 306i/266i/246i/226i G00-B6 and earlier, bizhub C759/C659 GC7-X8 and earlier, bizhub C658/C558/C458 GC7-X8 and earlier, bizhub 958/808/758 GC7-X8 and earlier, bizhub 658e/558e/458e GC7-X8 and earlier, bizhub C287/C227 GC7-X8 and earlier, bizhub 287/227 GC7-X8 and earlier, bizhub 368e/308e GC7-X8 and earlier, bizhub C368/C308/C258 GC9-X4 and earlier, bizhub 558/458/368/308 GC9-X4 and earlier, bizhub C754e/C654e GDQ-M0 and earlier, bizhub 754e/654e GDQ-M0 and earlier, bizhub C554e/C454e GDQ-M1 and earlier, bizhub C364e/C284e/C224e GDQ-M1 and earlier, bizhub 554e/454e/364e/284e/224e GDQ-M1 and earlier, bizhub C754/C654 C554/C454 GR1-M0 and earlier, bizhub C364/C284/C224 GR1-M0 and earlier, bizhub 754/654 GR1-M0 and earlier, bizhub C3851FS/C385 ...[truncated*]"
      }
    ]
  }
]

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

6.8

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

51.1%

Related for CVE-2021-20872