CVE-2023-46327
Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a facility to export the contents of their Address Book with encrypted form, but the encryption strength is insufficient. With the knowledge of the encryption process and the encryption key, the information such as the server credentials may be obtained from the exported Address Book data. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-46327?
CVE-2023-46327 is classified as a medium severity vulnerability due to the insufficient encryption used for the Address Book export feature in affected printers.
How do I fix CVE-2023-46327?
To mitigate CVE-2023-46327, it is recommended to apply firmware updates provided by FUJIFILM Business Innovation Corp. and Xerox Corporation as soon as they are available.
Which devices are affected by CVE-2023-46327?
CVE-2023-46327 impacts various models of FUJIFILM and Xerox multifunction printers that use specific firmware versions related to Address Book exports.
What are the potential risks associated with CVE-2023-46327?
The risks include unauthorized access to sensitive information stored in the Address Book due to weak encryption, potentially leading to data leaks.
Is there a workaround while waiting for a fix for CVE-2023-46327?
As a temporary measure, consider disabling the Address Book export feature if it is not necessary for operations until a patch has been applied.