CVE-2022-26320

CRITICAL
Published Mar 14, 20224y ago · Modified Jun 17, 20261w ago
9.1 CVSS 3.1
Critical
Find Similar
Published Mar 14, 2022 4y ago
Last Modified Jun 17, 2026 1w ago

Description

The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with Fermat's factorization method. This allows efficient calculation of private RSA keys from the public key of a TLS certificate.

CVSS Details

Base Score
9.1
Exploitability
3.9
Impact
5.2
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability None

Threat Intelligence

No active exploitation signals — not in CISA KEV and no EPSS score yet.

Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-330

Affected Products 183

VendorProductVersionRange
rambussafezone_basic_crypto_module*≥9.3.0  –  <10.4.0
fujifilmapeos_c7070_firmware* <1.1.7
fujifilmapeos_c7070*any
fujifilmapeos_c6570_firmware* <1.1.7
fujifilmapeos_c6570*any
fujifilmapeos_c5570_firmware* <1.1.7
fujifilmapeos_c5570*any
fujifilmapeos_c4570_firmware* <1.1.7
fujifilmapeos_c4570*any
fujifilmapeos_c3570_firmware* <1.1.7
fujifilmapeos_c3570*any
fujifilmapeos_c3070_firmware* <1.1.7
fujifilmapeos_c3070*any
fujifilmapeos_c7070_g_firmware* <1.1.7
fujifilmapeos_c7070_g*any
fujifilmapeos_c6570_g_firmware* <1.1.7
fujifilmapeos_c6570_g*any
fujifilmapeos_c5570_g_firmware* <1.1.7
fujifilmapeos_c5570_g*any
fujifilmapeos_c4570_g_firmware* <1.1.7
fujifilmapeos_c4570_g*any
fujifilmapeos_c3570_g_firmware* <1.1.7
fujifilmapeos_c3570_g*any
fujifilmapeos_c3070_g_firmware* <1.1.7
fujifilmapeos_c3070_g*any
fujifilmapeos_c328_df_firmware* <202112062053
fujifilmapeos_c328_df*any
fujifilmapeos_c328_dw_firmware* <202112062053
fujifilmapeos_c328_dw*any
fujifilmapeos_c325_dw_firmware* <202112062053
fujifilmapeos_c325_dw*any
fujifilmapeos_c325_z_firmware* <202112062053
fujifilmapeos_c325_z*any
fujifilmapeos_c8180_firmware* <1.1.6
fujifilmapeos_c8180*any
fujifilmapeos_c7580_firmware* <1.1.6
fujifilmapeos_c7580*any
fujifilmapeos_c6580_firmware* <1.1.6
fujifilmapeos_c6580*any
fujifilmapeosport_3560_firmware* <1.60.9
fujifilmapeosport_3560*any
fujifilmapeosport_3060_firmware* <1.60.9
fujifilmapeosport_3060*any
fujifilmapeosport_2560_firmware* <1.60.9
fujifilmapeosport_2560*any
fujifilmapeosport_3560_g_firmware* <1.60.9
fujifilmapeosport_3560_g*any
fujifilmapeosport_3060_g_firmware* <1.60.9
fujifilmapeosport_3060_g*any
fujifilmapeosport_2560_g_firmware* <1.60.9
fujifilmapeosport_2560_g*any
fujifilmapeosport_4570_g_firmware* <1.60.9
fujifilmapeosport_4570_g*any
fujifilmapeosport_5570_g_firmware* <1.60.9
fujifilmapeosport_5570_g*any
fujifilmapeosport_4570_firmware* <1.60.9
fujifilmapeosport_4570*any
fujifilmapeosport_5570_firmware* <1.60.9
fujifilmapeosport_5570*any
fujifilmapeosport_c3060_firmware* <1.60.9
fujifilmapeosport_c3060*any
fujifilmapeosport_c2560_firmware* <1.60.9
fujifilmapeosport_c2560*any
fujifilmapeosport_c2060_firmware* <1.60.9
fujifilmapeosport_c2060*any
fujifilmapeosport_c3060_firmware* <1.60.9
fujifilmapeosport_c3060*any
fujifilmapeosport_c2560_g_firmware* <1.60.9
fujifilmapeosport_c2560_g*any
fujifilmapeosport_c2060_g_firmware* <1.60.9
fujifilmapeosport_c2060_g*any
fujifilmapeosport_c7070_firmware* <1.60.9
fujifilmapeosport_c7070*any
fujifilmapeosport_c4570_firmware* <1.60.9
fujifilmapeosport_c4570*any
fujifilmapeosport_c3570_firmware* <1.60.9
fujifilmapeosport_c3570*any
fujifilmapeosport_c3070_firmware* <1.60.9
fujifilmapeosport_c3070*any
fujifilmapeosport_c6570_firmware* <1.60.9
fujifilmapeosport_c6570*any
fujifilmapeosport_c5570_firmware* <1.60.9
fujifilmapeosport_c5570*any
fujifilmapeosport_c7070_g_firmware* <1.60.9
fujifilmapeosport_c7070_g*any
fujifilmapeosport_c4570_g_firmware* <1.60.9
fujifilmapeosport_c4570_g*any
fujifilmapeosport_c3570_g_firmware* <1.60.9
fujifilmapeosport_c3570_g*any
fujifilmapeosport_c3070_g_firmware* <1.60.9
fujifilmapeosport_c3070_g*any
fujifilmapeosport_c6570_g_firmware* <1.60.9
fujifilmapeosport_c6570_g*any
fujifilmapeosport_c5570_g_firmware* <1.60.9
fujifilmapeosport_c5570_g*any
fujifilmapeosport_print_c5570_firmware* <1.60.9
fujifilmapeosport_print_c5570*any
fujifilmapeosport-vii_5021_firmware* <1.60.9
fujifilmapeosport-vii_5021*any
fujifilmapeosport-vii_p4021_firmware* <1.60.9
fujifilmapeosport-vii_p4021*any
fujifilmapeosport-vii_4021_firmware* <1.60.9
fujifilmapeosport-vii_4021*any
fujifilmapeosport-vii_cp4421_firmware* <1.60.9
fujifilmapeosport-vii_cp4421*any
fujifilmapeosport-vii_c4421_firmware* <1.60.9
fujifilmapeosport-vii_c4421*any
fujifilmapeosport-vii_c3321_firmware* <1.60.9
fujifilmapeosport-vii_c3321*any
fujifilmapeosport-vii_c7773_firmware* <1.60.2
fujifilmapeosport-vii_c7773*any
fujifilmapeosport-vii_c6773_firmware* <1.60.2
fujifilmapeosport-vii_c6773*any
fujifilmapeosport-vii_c5573_firmware* <1.60.2
fujifilmapeosport-vii_c5573*any
fujifilmapeosport-vii_c4473_firmware* <1.60.2
fujifilmapeosport-vii_c4473*any
fujifilmapeosport-vii_c3373_firmware* <1.60.2
fujifilmapeosport-vii_c3373*any
fujifilmapeosport-vii_c3372_firmware* <1.60.2
fujifilmapeosport-vii_c3372*any
fujifilmapeosport-vii_c2273_firmware* <1.60.2
fujifilmapeosport-vii_c2273*any
fujifilmapeosport-vii_c7788_firmware* <1.60.1
fujifilmapeosport-vii_c7788*any
fujifilmapeosport-vii_c6688_firmware* <1.60.1
fujifilmapeosport-vii_c6688*any
fujifilmapeosport-vii_c5588_firmware* <1.60.1
fujifilmapeosport-vii_c5588*any
fujifilmapeospro_c810_firmware* <1.1.6
fujifilmapeospro_c810*any
fujifilmapeospro_c750_firmware* <1.1.6
fujifilmapeospro_c750*any
fujifilmapeospro_c650_firmware* <1.1.6
fujifilmapeospro_c650*any
fujifilmapeosprint_c328_firmware* <202112062117
fujifilmapeosprint_c328*any
fujifilmapeosprint_c328_dw_firmware* <202112062117
fujifilmapeosprint_c328_dw*any
fujifilmapeosprint_c325_dw_firmware* <202112062117
fujifilmapeosprint_c325_dw*any
fujifilmdocucentre-vii_c7773_firmware* <1.60.2
fujifilmdocucentre-vii_c7773*any
fujifilmdocucentre-vii_c6673_firmware* <1.60.2
fujifilmdocucentre-vii_c6673*any
fujifilmdocucentre-vii_c5573_firmware* <1.60.2
fujifilmdocucentre-vii_c5573*any
fujifilmdocucentre-vii_c4473_firmware* <1.60.2
fujifilmdocucentre-vii_c4473*any
fujifilmdocucentre-vii_c3373_firmware* <1.60.2
fujifilmdocucentre-vii_c3373*any
fujifilmdocucentre-vii_c3372_firmware* <1.60.2
fujifilmdocucentre-vii_c3372*any
fujifilmdocucentre-vii_c2273_firmware* <1.60.2
fujifilmdocucentre-vii_c2273*any
fujifilmdocucentre-vii_c7788_firmware* <1.60.1
fujifilmdocucentre-vii_c7788*any
fujifilmdocucentre-vii_c6688_firmware* <1.60.1
fujifilmdocucentre-vii_c6688*any
fujifilmdocucentre-vii_c5588_firmware* <1.60.1
fujifilmdocucentre-vii_c5588*any
fujifilmdocuprint_4405_d_firmware* <1.57.5
fujifilmdocuprint_4405_d*any
fujifilmdocuprint_4408_d_firmware* <1.57.5
fujifilmdocuprint_4408_d*any
fujifilmdocuprint_3505_d_firmware* <1.57.5
fujifilmdocuprint_3505_d*any
fujifilmdocuprint_3508_d_firmware* <1.57.5
fujifilmdocuprint_3508_d*any
fujifilmdocuprint_3205_d_firmware* <1.57.5
fujifilmdocuprint_3205_d*any
fujifilmdocuprint_3208_d_firmware* <1.57.5
fujifilmdocuprint_3208_d*any
fujifilmdocuprint_c3555_d_firmware* <1.57.6
fujifilmdocuprint_c3555_d*any
fujifilmdocuprint_c2555_d_firmware* <1.57.6
fujifilmdocuprint_c2555_d*any
fujifilmprimelink_c9070_firmware* <1.145.1
fujifilmprimelink_c9070*any
fujifilmprimelink_c9065_firmware* <1.145.1
fujifilmprimelink_c9065*any
canonimagerunner_firmware* ≤2020-03-14
canonimageprograf_firmware* <2020-03-14

References 6

  • fermatattack.secvuln.info https://fermatattack.secvuln.info
    Third Party Advisory
  • global.canon https://global.canon/en/support/security/index.html
    Third Party Advisory
  • safezoneswupdate.com https://safezoneswupdate.com
  • web.archive.org https://web.archive.org/web/20220922042721/https://safezoneswupdate.com/
  • fujifilm.com https://www.fujifilm.com/fbglobal/eng/company/news/notice/2022/0302_rsakey_announce.html
    MitigationThird Party Advisory
  • rambus.com https://www.rambus.com/security/response-center/advisories/rmbs-2021-01/

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.