CVE-2022-29588

HIGH

Konica Minolta bizhub MFP Firmware < 2022-04-14 - Insufficiently Protected Credentials

Title source: llm
STIX 2.1

Description

Konica Minolta bizhub MFP devices before 2022-04-14 use cleartext password storage for the /var/log/nginx/html/ADMINPASS and /etc/shadow files.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://sec-consult.com/vulnerability-lab/

Scores

CVSS v3 7.5
EPSS 0.0163
EPSS Percentile 73.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-522
Status published
Products (45)
konicaminolta/bizhub_226i_firmware < 2022-04-14
konicaminolta/bizhub_227_firmware < 2022-04-14
konicaminolta/bizhub_246i_firmware < 2022-04-14
konicaminolta/bizhub_287_firmware < 2022-04-14
konicaminolta/bizhub_306i_firmware < 2022-04-14
konicaminolta/bizhub_308_firmware < 2022-04-14
konicaminolta/bizhub_308e_firmware < 2022-04-14
konicaminolta/bizhub_367_firmware < 2022-04-14
konicaminolta/bizhub_368_firmware < 2022-04-14
konicaminolta/bizhub_368e_firmware < 2022-04-14
... and 35 more
Published May 16, 2022
Tracked Since Feb 18, 2026