A risky-algorithm issue was discovered on Fujifilm DocuCentre-VI C4471 1.8 devices. An attacker that obtained access to the administrative web interface of a printer (e.g., by using the default credentials) can download the address book file, which contains the list of users (domain users, FTP users, etc.) stored on the printer, together with their encrypted passwords. The passwords are protected by a weak cipher, such as ROT13, which requires minimal effort to instantly retrieve the original password, giving the attacker a list of valid domain or FTP usernames and passwords.

Project Subscriptions

Vendors Products
Fujifilm Subscribe
Apeosport-iv 2060 Subscribe
Apeosport-iv 2060 Firmware Subscribe
Apeosport-iv 3060 Subscribe
Apeosport-iv 3060 Firmware Subscribe
Apeosport-iv 3065 Subscribe
Apeosport-iv 3065 Firmware Subscribe
Apeosport-iv 3070 Subscribe
Apeosport-iv 3070 Firmware Subscribe
Apeosport-iv 4070 Subscribe
Apeosport-iv 4070 Firmware Subscribe
Apeosport-iv 5070 Subscribe
Apeosport-iv 5070 Firmware Subscribe
Apeosport-iv 5080 Subscribe
Apeosport-iv 5080 Firmware Subscribe
Apeosport-iv 6080 Subscribe
Apeosport-iv 6080 Firmware Subscribe
Apeosport-iv 7080 Subscribe
Apeosport-iv 7080 Firmware Subscribe
Apeosport-iv C2270 Subscribe
Apeosport-iv C2270 Firmware Subscribe
Apeosport-iv C2275 Subscribe
Apeosport-iv C2275 Firmware Subscribe
Apeosport-iv C3370 Subscribe
Apeosport-iv C3370 Firmware Subscribe
Apeosport-iv C3375 Subscribe
Apeosport-iv C3375 Firmware Subscribe
Apeosport-iv C4430 Subscribe
Apeosport-iv C4430 Firmware Subscribe
Apeosport-iv C4470 Subscribe
Apeosport-iv C4470 Firmware Subscribe
Apeosport-iv C4475 Subscribe
Apeosport-iv C4475 Firmware Subscribe
Apeosport-iv C5570 Subscribe
Apeosport-iv C5570 Firmware Subscribe
Apeosport-iv C5575 Subscribe
Apeosport-iv C5575 Firmware Subscribe
Apeosport-iv C5580 Subscribe
Apeosport-iv C5580 Firmware Subscribe
Apeosport-iv C6680 Subscribe
Apeosport-iv C6680 Firmware Subscribe
Apeosport-iv C7780 Subscribe
Apeosport-iv C7780 Firmware Subscribe
Apeosport-v 4020 Subscribe
Apeosport-v 4020 Firmware Subscribe
Apeosport-v 4070 Subscribe
Apeosport-v 4070 Firmware Subscribe
Apeosport-v 5070 Subscribe
Apeosport-v 5070 Firmware Subscribe
Apeosport-v C2275 Subscribe
Apeosport-v C2275 Firmware Subscribe
Apeosport-v C2275 T2 Subscribe
Apeosport-v C2275 T2 Firmware Subscribe
Apeosport-v C2276 Subscribe
Apeosport-v C2276 Firmware Subscribe
Apeosport-v C3320 Subscribe
Apeosport-v C3320 Firmware Subscribe
Apeosport-v C3373 T2 Subscribe
Apeosport-v C3373 T2 Firmware Subscribe
Apeosport-v C3375 Subscribe
Apeosport-v C3375 Firmware Subscribe
Apeosport-v C3375 T2 Subscribe
Apeosport-v C3375 T2 Firmware Subscribe
Apeosport-v C3376 Subscribe
Apeosport-v C3376 Firmware Subscribe
Apeosport-v C4475 Subscribe
Apeosport-v C4475 Firmware Subscribe
Apeosport-v C4475 T2 Subscribe
Apeosport-v C4475 T2 Firmware Subscribe
Apeosport-v C4476 Subscribe
Apeosport-v C4476 Firmware Subscribe
Apeosport-v C5575 Subscribe
Apeosport-v C5575 Firmware Subscribe
Apeosport-v C5575 T2 Subscribe
Apeosport-v C5575 T2 Firmware Subscribe
Apeosport-v C5576 Subscribe
Apeosport-v C5576 Firmware Subscribe
Apeosport-v C5580 Subscribe
Apeosport-v C5580 Firmware Subscribe
Apeosport-v C5580 T2 Subscribe
Apeosport-v C5580 T2 Firmware Subscribe
Apeosport-v C5585 Subscribe
Apeosport-v C5585 Firmware Subscribe
Apeosport-v C6675 Subscribe
Apeosport-v C6675 Firmware Subscribe
Apeosport-v C6675 T2 Subscribe
Apeosport-v C6675 T2 Firmware Subscribe
Apeosport-v C6676 Subscribe
Apeosport-v C6676 Firmware Subscribe
Apeosport-v C6680 Subscribe
Apeosport-v C6680 Firmware Subscribe
Apeosport-v C6680 T2 Subscribe
Apeosport-v C6680 T2 Firmware Subscribe
Apeosport-v C6685 Subscribe
Apeosport-v C6685 Firmware Subscribe
Apeosport-v C7775 Subscribe
Apeosport-v C7775 Firmware Subscribe
Apeosport-v C7775 T2 Subscribe
Apeosport-v C7775 T2 Firmware Subscribe
Apeosport-v C7776 Subscribe
Apeosport-v C7776 Firmware Subscribe
Apeosport-v C7780 Subscribe
Apeosport-v C7780 Firmware Subscribe
Apeosport-v C7780 T2 Subscribe
Apeosport-v C7780 T2 Firmware Subscribe
Apeosport-v C7785 Subscribe
Apeosport-v C7785 Firmware Subscribe
Apeosport-vi C2271 Subscribe
Apeosport-vi C2271 Firmware Subscribe
Apeosport-vi C3370 Subscribe
Apeosport-vi C3370 Firmware Subscribe
Apeosport-vi C3371 Subscribe
Apeosport-vi C3371 Firmware Subscribe
Apeosport-vi C4471 Subscribe
Apeosport-vi C4471 Firmware Subscribe
Apeosport-vi C5571 Subscribe
Apeosport-vi C5571 Firmware Subscribe
Apeosport-vi C6671 Subscribe
Apeosport-vi C6671 Firmware Subscribe
Apeosport-vi C7771 Subscribe
Apeosport-vi C7771 Firmware Subscribe
Apeosport-vii C2273 Subscribe
Apeosport-vii C2273 Firmware Subscribe
Apeosport-vii C3372 Subscribe
Apeosport-vii C3372 Firmware Subscribe
Apeosport-vii C3373 Subscribe
Apeosport-vii C3373 Firmware Subscribe
Apeosport-vii C4473 Subscribe
Apeosport-vii C4473 Firmware Subscribe
Apeosport-vii C5573 Subscribe
Apeosport-vii C5573 Firmware Subscribe
Apeosport-vii C6673 Subscribe
Apeosport-vii C6673 Firmware Subscribe
Apeosport-vii C7773 Subscribe
Apeosport-vii C7773 Firmware Subscribe
Docucentre-iv 2060 Subscribe
Docucentre-iv 2060 Firmware Subscribe
Docucentre-iv 3060 Subscribe
Docucentre-iv 3060 Firmware Subscribe
Docucentre-iv 4070 Subscribe
Docucentre-iv 4070 Firmware Subscribe
Docucentre-iv 5070 Subscribe
Docucentre-iv 5070 Firmware Subscribe
Docucentre-iv 5080 Subscribe
Docucentre-iv 5080 Firmware Subscribe
Docucentre-iv 6080 Subscribe
Docucentre-iv 6080 Firmware Subscribe
Docucentre-iv 7080 Subscribe
Docucentre-iv 7080 Firmware Subscribe
Docucentre-iv C2260 Subscribe
Docucentre-iv C2260 Firmware Subscribe
Docucentre-iv C2263 Subscribe
Docucentre-iv C2263 Firmware Subscribe
Docucentre-iv C2265 Subscribe
Docucentre-iv C2265 Firmware Subscribe
Docucentre-iv C2270 Subscribe
Docucentre-iv C2270 Firmware Subscribe
Docucentre-iv C2275 Subscribe
Docucentre-iv C2275 Firmware Subscribe
Docucentre-iv C3370 Subscribe
Docucentre-iv C3370 Firmware Subscribe
Docucentre-iv C3375 Subscribe
Docucentre-iv C3375 Firmware Subscribe
Docucentre-iv C4430 Subscribe
Docucentre-iv C4430 Firmware Subscribe
Docucentre-iv C4470 Subscribe
Docucentre-iv C4470 Firmware Subscribe
Docucentre-iv C4475 Subscribe
Docucentre-iv C4475 Firmware Subscribe
Docucentre-iv C5570 Subscribe
Docucentre-iv C5570 Firmware Subscribe
Docucentre-iv C5575 Subscribe
Docucentre-iv C5575 Firmware Subscribe
Docucentre-iv C5580 Subscribe
Docucentre-iv C5580 Firmware Subscribe
Docucentre-iv C6680 Subscribe
Docucentre-iv C6680 Firmware Subscribe
Docucentre-iv C7780 Subscribe
Docucentre-iv C7780 Firmware Subscribe
Docucentre-v 1060 Subscribe
Docucentre-v 1060 Firmware Subscribe
Docucentre-v 2060 Subscribe
Docucentre-v 2060 Firmware Subscribe
Docucentre-v 3060 Subscribe
Docucentre-v 3060 Firmware Subscribe
Docucentre-v 4070 Subscribe
Docucentre-v 4070 Firmware Subscribe
Docucentre-v 5070 Subscribe
Docucentre-v 5070 Firmware Subscribe
Docucentre-v 5080 Subscribe
Docucentre-v 5080 Firmware Subscribe
Docucentre-v 6080 Subscribe
Docucentre-v 6080 Firmware Subscribe
Docucentre-v 7080 Subscribe
Docucentre-v 7080 Firmware Subscribe
Docucentre-v C2263 Subscribe
Docucentre-v C2263 Firmware Subscribe
Docucentre-v C2265 Subscribe
Docucentre-v C2265 Firmware Subscribe
Docucentre-v C2275 Subscribe
Docucentre-v C2275 Firmware Subscribe
Docucentre-v C2275 T2 Subscribe
Docucentre-v C2275 T2 Firmware Subscribe
Docucentre-v C2276 Subscribe
Docucentre-v C2276 Firmware Subscribe
Docucentre-v C3373 T2 Subscribe
Docucentre-v C3373 T2 Firmware Subscribe
Docucentre-v C3375 Subscribe
Docucentre-v C3375 Firmware Subscribe
Docucentre-v C3375 T2 Subscribe
Docucentre-v C3375 T2 Firmware Subscribe
Docucentre-v C3376 Subscribe
Docucentre-v C3376 Firmware Subscribe
Docucentre-v C4475 Subscribe
Docucentre-v C4475 Firmware Subscribe
Docucentre-v C4475 T2 Subscribe
Docucentre-v C4475 T2 Firmware Subscribe
Docucentre-v C4476 Subscribe
Docucentre-v C4476 Firmware Subscribe
Docucentre-v C5575 Subscribe
Docucentre-v C5575 Firmware Subscribe
Docucentre-v C5575 T2 Subscribe
Docucentre-v C5575 T2 Firmware Subscribe
Docucentre-v C5576 Subscribe
Docucentre-v C5576 Firmware Subscribe
Docucentre-v C5580 Subscribe
Docucentre-v C5580 Firmware Subscribe
Docucentre-v C5580 T2 Subscribe
Docucentre-v C5580 T2 Firmware Subscribe
Docucentre-v C5585 Subscribe
Docucentre-v C5585 Firmware Subscribe
Docucentre-v C6675 Subscribe
Docucentre-v C6675 Firmware Subscribe
Docucentre-v C6675 T2 Subscribe
Docucentre-v C6675 T2 Firmware Subscribe
Docucentre-v C6676 Subscribe
Docucentre-v C6676 Firmware Subscribe
Docucentre-v C6680 Subscribe
Docucentre-v C6680 Firmware Subscribe
Docucentre-v C6680 T2 Subscribe
Docucentre-v C6680 T2 Firmware Subscribe
Docucentre-v C6685 Subscribe
Docucentre-v C6685 Firmware Subscribe
Docucentre-v C7775 Subscribe
Docucentre-v C7775 Firmware Subscribe
Docucentre-v C7775 T2 Subscribe
Docucentre-v C7775 T2 Firmware Subscribe
Docucentre-v C7776 Subscribe
Docucentre-v C7776 Firmware Subscribe
Docucentre-v C7780 Subscribe
Docucentre-v C7780 Firmware Subscribe
Docucentre-v C7780 T2 Subscribe
Docucentre-v C7780 T2 Firmware Subscribe
Docucentre-v C7785 Subscribe
Docucentre-v C7785 Firmware Subscribe
Docucentre-vi C2271 Subscribe
Docucentre-vi C2271 Firmware Subscribe
Docucentre-vi C3370 Subscribe
Docucentre-vi C3370 Firmware Subscribe
Docucentre-vi C3371 Subscribe
Docucentre-vi C3371 Firmware Subscribe
Docucentre-vi C4471 Subscribe
Docucentre-vi C4471 Firmware Subscribe
Docucentre-vi C5571 Subscribe
Docucentre-vi C5571 Firmware Subscribe
Docucentre-vi C6671 Subscribe
Docucentre-vi C6671 Firmware Subscribe
Docucentre-vi C7771 Subscribe
Docucentre-vi C7771 Firmware Subscribe
Docucentre-vii C2273 Subscribe
Docucentre-vii C2273 Firmware Subscribe
Docucentre-vii C3372 Subscribe
Docucentre-vii C3372 Firmware Subscribe
Docucentre-vii C3373 Subscribe
Docucentre-vii C3373 Firmware Subscribe
Docucentre-vii C4473 Subscribe
Docucentre-vii C4473 Firmware Subscribe
Docucentre-vii C5573 Subscribe
Docucentre-vii C5573 Firmware Subscribe
Docucentre-vii C6673 Subscribe
Docucentre-vii C6673 Firmware Subscribe
Docucentre-vii C7773 Subscribe
Docucentre-vii C7773 Firmware Subscribe
Docucolor 1450 Ga Subscribe
Docucolor 1450 Ga Firmware Subscribe
Docuprint Cm415 Ap Subscribe
Docuprint Cm415 Ap Firmware Subscribe
Docuprint Cm505da Subscribe
Docuprint Cm505da Firmware Subscribe
Docuprint M465 Ap Subscribe
Docuprint M465 Ap Firmware Subscribe
Fuji Xerox B9100 Subscribe
Fuji Xerox B9100 Firmware Subscribe
Fuji Xerox B9110 Subscribe
Fuji Xerox B9110 Firmware Subscribe
Fuji Xerox B9125 Subscribe
Fuji Xerox B9125 Firmware Subscribe
Fuji Xerox B9136 Subscribe
Fuji Xerox B9136 Firmware Subscribe
Fuji Xerox Color C60 Subscribe
Fuji Xerox Color C60 Firmware Subscribe
Fuji Xerox Color C70 Subscribe
Fuji Xerox Color C70 Firmware Subscribe
Fuji Xerox Color C75 Subscribe
Fuji Xerox Color C75 Firmware Subscribe
Fuji Xerox D110 Subscribe
Fuji Xerox D110 Firmware Subscribe
Fuji Xerox D125 Subscribe
Fuji Xerox D125 Firmware Subscribe
Fuji Xerox D136 Subscribe
Fuji Xerox D136 Firmware Subscribe
Fuji Xerox D95 Subscribe
Fuji Xerox D95 Firmware Subscribe
Versant 170i Subscribe
Versant 170i Firmware Subscribe
Versant 180 Subscribe
Versant 180 Firmware Subscribe
Versant 180i Subscribe
Versant 180i Firmware Subscribe
Versant 80 Subscribe
Versant 80 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-30681 A risky-algorithm issue was discovered on Fujifilm DocuCentre-VI C4471 1.8 devices. An attacker that obtained access to the administrative web interface of a printer (e.g., by using the default credentials) can download the address book file, which contains the list of users (domain users, FTP users, etc.) stored on the printer, together with their encrypted passwords. The passwords are protected by a weak cipher, such as ROT13, which requires minimal effort to instantly retrieve the original password, giving the attacker a list of valid domain or FTP usernames and passwords.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T04:03:08.961Z

Reserved: 2021-11-16T00:00:00

Link: CVE-2021-43774

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-03-03T15:15:08.483

Modified: 2024-11-21T06:29:45.363

Link: CVE-2021-43774

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses