Description
Session information easily guessable vulnerability exists in Kyocera Document Solutions MFPs and printers, which may allow a network-adjacent attacker to log in to the product by spoofing a user with guessed session information. Affected products/versions are as follows: TASKalfa 7550ci/6550ci, TASKalfa 5550ci/4550ci/3550ci/3050ci, TASKalfa 255c/205c, TASKalfa 256ci/206ci, ECOSYS M6526cdn/M6526cidn, FS-C2126MFP/C2126MFP+/C2026MFP/C2026MFP+, TASKalfa 8000i/6500i, TASKalfa 5500i/4500i/3500i, TASKalfa 305/255, TASKalfa 306i/256i, LS-3140MFP/3140MFP+/3640MFP, ECOSYS M2535dn, LS-1135MFP/1035MFP, LS-C8650DN/C8600DN, ECOSYS P6026cdn, FS-C5250DN, LS-4300DN/4200DN/2100DN, ECOSYS P4040dn, ECOSYS P2135dn, and FS-1370DN.
Published: 2022-12-05
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-44966 Session information easily guessable vulnerability exists in Kyocera Document Solutions MFPs and printers, which may allow a network-adjacent attacker to log in to the product by spoofing a user with guessed session information. Affected products/versions are as follows: TASKalfa 7550ci/6550ci, TASKalfa 5550ci/4550ci/3550ci/3050ci, TASKalfa 255c/205c, TASKalfa 256ci/206ci, ECOSYS M6526cdn/M6526cidn, FS-C2126MFP/C2126MFP+/C2026MFP/C2026MFP+, TASKalfa 8000i/6500i, TASKalfa 5500i/4500i/3500i, TASKalfa 305/255, TASKalfa 306i/256i, LS-3140MFP/3140MFP+/3640MFP, ECOSYS M2535dn, LS-1135MFP/1035MFP, LS-C8650DN/C8600DN, ECOSYS P6026cdn, FS-C5250DN, LS-4300DN/4200DN/2100DN, ECOSYS P4040dn, ECOSYS P2135dn, and FS-1370DN.
History

Thu, 24 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Kyocera Ecosys M2535dn Ecosys M2535dn Firmware Ecosys M6526cdn Ecosys M6526cdn Firmware Ecosys M6526cidn Ecosys M6526cidn Firmware Ecosys P2135dn Ecosys P2135dn Firmware Ecosys P4040dn Ecosys P4040dn Firmware Ecosys P6026cdn Ecosys P6026cdn Firmware Fs-1370dn Fs-1370dn Firmware Fs-c2026mfp Fs-c2026mfp Firmware Fs-c2126mfp Fs-c2126mfp\+ Fs-c2126mfp\+ Firmware Fs-c2126mfp Firmware Fs-c5250dn Fs-c5250dn Firmware Ls-1035mfp Ls-1035mfp Firmware Ls-1135mfp Ls-1135mfp Firmware Ls-2100dn Ls-2100dn Firmware Ls-3140mfp Ls-3140mfp\+ Ls-3140mfp\+ Firmware Ls-3140mfp Firmware Ls-3640mfp Ls-3640mfp Firmware Ls-4200dn Ls-4200dn Firmware Ls-4300dn Ls-4300dn Firmware Ls-c8600dn Ls-c8600dn Firmware Ls-c8650dn Ls-c8650dn Firmware Taskalfa 205c Taskalfa 205c Firmware Taskalfa 206ci Taskalfa 206ci Firmware Taskalfa 255 Taskalfa 255 Firmware Taskalfa 255c Taskalfa 255c Firmware Taskalfa 256ci Taskalfa 256ci Firmware Taskalfa 256i Taskalfa 256i Firmware Taskalfa 305 Taskalfa 3050ci Taskalfa 3050ci Firmware Taskalfa 305 Firmware Taskalfa 306i Taskalfa 306i Firmware Taskalfa 3500i Taskalfa 3500i Firmware Taskalfa 3550ci Taskalfa 3550ci Firmware Taskalfa 4500i Taskalfa 4500i Firmware Taskalfa 4550ci Taskalfa 4550ci Firmware Taskalfa 5500i Taskalfa 5500i Firmware Taskalfa 5550ci Taskalfa 5550ci Firmware Taskalfa 6500i Taskalfa 6500i Firmware Taskalfa 6550ci Taskalfa 6550ci Firmware Taskalfa 7550ci Taskalfa 7550ci Firmware Taskalfa 8000i Taskalfa 8000i Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2025-04-24T14:30:52.508Z

Reserved: 2022-10-22T00:00:00.000Z

Link: CVE-2022-41798

cve-icon Vulnrichment

Updated: 2024-08-03T12:56:37.889Z

cve-icon NVD

Status : Modified

Published: 2022-12-05T04:15:09.967

Modified: 2025-04-24T15:15:49.100

Link: CVE-2022-41798

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses