CVE-2021-20872
6.8
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.9 / Impact: 5.9
Source: NVD
Description
Protection mechanism failure vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G00-35 and earlier, bizhub C650i/C550i/C450i G00-B6 and earlier, bizhub C360i/C300i/C250i G00-B6 and earlier, bizhub 750i/650i/550i/450i G00-37 and earlier, bizhub 360i/300i G00-33 and earlier, bizhub C287i/C257i/C227i G00-19 and earlier, bizhub 306i/266i/246i/226i G00-B6 and earlier, bizhub C759/C659 GC7-X8 and earlier, bizhub C658/C558/C458 GC7-X8 and earlier, bizhub 958/808/758 GC7-X8 and earlier, bizhub 658e/558e/458e GC7-X8 and earlier, bizhub C287/C227 GC7-X8 and earlier, bizhub 287/227 GC7-X8 and earlier, bizhub 368e/308e GC7-X8 and earlier, bizhub C368/C308/C258 GC9-X4 and earlier, bizhub 558/458/368/308 GC9-X4 and earlier, bizhub C754e/C654e GDQ-M0 and earlier, bizhub 754e/654e GDQ-M0 and earlier, bizhub C554e/C454e GDQ-M1 and earlier, bizhub C364e/C284e/C224e GDQ-M1 and earlier, bizhub 554e/454e/364e/284e/224e GDQ-M1 and earlier, bizhub C754/C654 C554/C454 GR1-M0 and earlier, bizhub C364/C284/C224 GR1-M0 and earlier, bizhub 754/654 GR1-M0 and earlier, bizhub C3851FS/C3851/C3351 GC9-X4 and earlier, bizhub 4752/4052 GC9-X4 and earlier) allows a physical attacker to bypass the firmware integrity verification and to install malicious firmware.
Affected (52)
Products: Konicaminolta: Bizhub C759 Firmware, Bizhub C659 Firmware, Bizhub C658 Firmware, Bizhub C558 Firmware, Bizhub C458 Firmware, Bizhub 958 Firmware, Bizhub 808 Firmware, Bizhub 758 Firmware, Bizhub 658e Firmware, Bizhub 558e Firmware, Bizhub 458e Firmware, Bizhub C287 Firmware, Bizhub C227 Firmware, Bizhub 287 Firmware, Bizhub 227 Firmware, Bizhub 368e Firmware, Bizhub 308e Firmware, Bizhub C368 Firmware, Bizhub C308 Firmware, Bizhub C258 Firmware, Bizhub 558 Firmware, Bizhub 458 Firmware, Bizhub 368 Firmware, Bizhub 308 Firmware, Bizhub C754e Firmware, Bizhub C654e Firmware, Bizhub 754e Firmware, Bizhub 654e Firmware, Bizhub C554e Firmware, Bizhub C454e Firmware, Bizhub C364e Firmware, Bizhub C284e Firmware, Bizhub C224e Firmware, Bizhub 554e Firmware, Bizhub 454e Firmware, Bizhub 364e Firmware, Bizhub 284e Firmware, Bizhub 224e Firmware, Bizhub C754 Firmware, Bizhub C654 Firmware, Bizhub C554 Firmware, Bizhub C454 Firmware, Bizhub C364 Firmware, Bizhub C284 Firmware, Bizhub C224 Firmware, Bizhub 754 Firmware, Bizhub 654 Firmware, Bizhub C3851fs Firmware, Bizhub C3851 Firmware, Bizhub C3351 Firmware, Bizhub 4752 Firmware, Bizhub 4052 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-y1 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C759 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-y1 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C659 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-y1 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C658 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-y1 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C558 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-y1 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C458 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-y1 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub 958 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-y1 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub 808 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-y1 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub 758 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-y1 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub 658e | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-y1 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub 558e | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-y1 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub 458e | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-y0 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C287 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-y0 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C227 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-y0 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub 287 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-y0 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub 227 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-x8 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub 368e | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-x8 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub 308e | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-x4 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C368 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-x4 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C308 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-x4 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C258 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-x4 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub 558 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-x4 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub 458 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-x4 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub 368 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-x4 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub 308 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before gdr-m0 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C754e | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before gdr-m0 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C654e | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before gdr-m0 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub 754e | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before gdr-m0 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub 654e | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before gdr-m1 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C554e | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before gdr-m1 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C454e | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before gdr-m1 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C364e | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before gdr-m1 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C284e | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before gdr-m1 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C224e | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before gdr-m1 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub 554e | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before gdr-m1 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub 454e | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before gdr-m1 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub 364e | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before gdr-m1 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub 284e | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before gdr-m1 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub 224e | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before gr4-m0 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C754 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before gr4-m0 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C654 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before gr4-m0 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C554 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before gr4-m0 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C454 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before gr4-m0 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C364 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before gr4-m0 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C284 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before gr4-m0 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C224 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before gr4-m0 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub 754 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before gr4-m0 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub 654 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-x4 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C3851fs | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-x4 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C3851 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-x4 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub C3351 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-x4 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub 4752 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before gca-x4 |
| Running on/with | Platform Versions |
|---|---|
Konicaminolta Bizhub 4052 | All versions |
References (8)
Source: vultures@jpcert.or.jp
Third Party AdvisoryVDB Entry
Source: vultures@jpcert.or.jp
Third Party AdvisoryVDB Entry
Source: vultures@jpcert.or.jp
MitigationVendor Advisory
Source: vultures@jpcert.or.jp
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Timeline
No history available yet.