CVE-2022-26320
CRITICALRambus SafeZone Basic Crypto Module <10.4.0 - Info Disclosure
Title source: llmDescription
The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with Fermat's factorization method. This allows efficient calculation of private RSA keys from the public key of a TLS certificate.
References (6)
Scores
CVSS v3
9.1
EPSS
0.0038
EPSS Percentile
59.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Details
CWE
CWE-330
Status
published
Products (50)
canon/imageprograf_firmware
< 2020-03-14
canon/imagerunner_firmware
< 2020-03-14
fujifilm/apeos_c3070_firmware
< 1.1.7
fujifilm/apeos_c3070_g_firmware
< 1.1.7
fujifilm/apeos_c325_dw_firmware
< 202112062053
fujifilm/apeos_c325_z_firmware
< 202112062053
fujifilm/apeos_c328_df_firmware
< 202112062053
fujifilm/apeos_c328_dw_firmware
< 202112062053
fujifilm/apeos_c3570_firmware
< 1.1.7
fujifilm/apeos_c3570_g_firmware
< 1.1.7
... and 40 more
Published
Mar 14, 2022
Tracked Since
Feb 18, 2026