CVE-2022-26320
This allows efficient calculation of private RSA keys from the public key of a TLS certificate.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.97%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with Fermat's factorization method. This allows efficient calculation of private RSA keys from the public key of a TLS certificate.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 0.97% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-330
- Affected
- rambus/safezone basic crypto module · fujifilm/apeos c7070 firmware · fujifilm/apeos c6570 firmware · fujifilm/apeos c5570 firmware · fujifilm/apeos c4570 firmware · fujifilm/apeos c3570 firmware · fujifilm/apeos c3070 firmware · fujifilm/apeos c7070 g firmware · fujifilm/apeos c6570 g firmware · fujifilm/apeos c5570 g firmware · fujifilm/apeos c4570 g firmware · fujifilm/apeos c3570 g firmware · fujifilm/apeos c3070 g firmware · fujifilm/apeos c328 df firmware · fujifilm/apeos c328 dw firmware · fujifilm/apeos c325 dw firmware · fujifilm/apeos c325 z firmware · fujifilm/apeos c8180 firmware · fujifilm/apeos c7580 firmware · fujifilm/apeos c6580 firmware · +40 more
- Source
- cve@mitre.org
References
- https://fermatattack.secvuln.infoThird Party Advisory
- https://global.canon/en/support/security/index.htmlThird Party Advisory
- https://web.archive.org/web/20220922042721/https://safezoneswupdate.com/
- https://www.fujifilm.com/fbglobal/eng/company/news/notice/2022/0302_rsakey_announce.htmlMitigation, Third Party Advisory
- https://www.rambus.com/security/response-center/advisories/rmbs-2021-01/
- https://fermatattack.secvuln.infoThird Party Advisory
- https://global.canon/en/support/security/index.htmlThird Party Advisory
- https://safezoneswupdate.com
- https://www.fujifilm.com/fbglobal/eng/company/news/notice/2022/0302_rsakey_announce.htmlMitigation, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.