VYPR
Vendor

Fujifilm

Products
315
CVEs
13
Across products
60
Status
Private

Products

315
View all 315 products →

Recent CVEs

13
  • CVE-2019-10950CriApr 30, 2019
    risk 0.64cvss 9.8epss 0.04

    Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X provide insecure telnet services that lack authentication requirements. An attacker who successfully exploits this vulnerability may be able to access…

  • CVE-2022-26320CriMar 14, 2022
    risk 0.59cvss 9.1epss 0.01

    The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with…

  • CVE-2017-10850HigSep 1, 2017
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in Installers of ART EX Driver for ApeosPort-VI C7771/C6671/C5571/C4471/C3371/C2271, DocuCentre-VI C7771/C6671/C5571/C4471/C3371/C2271 (Timestamp of code signing is before 12 Apr 2017 02:04 UTC.), PostScript? Driver + Additional Feature…

  • CVE-2023-29984HigJul 11, 2023
    risk 0.49cvss 7.5epss 0.01

    Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As for the affected…

  • CVE-2022-43460HigFeb 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Driver Distributor v2.2.3.1 and earlier contains a vulnerability where passwords are stored in a recoverable format. If an attacker obtains a configuration file of Driver Distributor, the encrypted administrator's credentials may be decrypted.

  • CVE-2019-10948HigApr 30, 2019
    risk 0.49cvss 7.5epss 0.02

    Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X are susceptible to a denial-of-service condition as a result of an overflow of TCP packets, which requires the device to be manually rebooted.

  • CVE-2026-21408HigJan 27, 2026
    risk 0.47cvss 7.3epss 0.00

    beat-access for Windows version 3.0.3 and prior contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with SYSTEM privileges.

  • CVE-2024-45320MedFeb 18, 2025
    risk 0.42cvss 6.5epss 0.00

    Out-of-bounds write vulnerability exists in DocuPrint CP225w 01.22.01 and earlier, DocuPrint CP228w 01.22.01 and earlier, DocuPrint CM225fw 01.10.01 and earlier, and DocuPrint CM228fw 01.10.01 and earlier. If an affected MFP processes a specially crafted printer job file, a…

  • CVE-2024-27974MedMar 18, 2024
    risk 0.41cvss 6.3epss 0.00

    Cross-site request forgery vulnerability in FUJIFILM printers which implement CentreWare Internet Services or Internet Services allows a remote unauthenticated attacker to alter user information. In the case the user is an administrator, the settings such as the administrator's…

  • CVE-2023-46327MedNov 2, 2023
    risk 0.38cvss 5.9epss 0.00

    Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a facility to export the contents of their Address Book with encrypted form, but the encryption strength is insufficient. With the knowledge of the encryption…

  • CVE-2025-48499MedAug 4, 2025
    risk 0.34cvss 5.3epss 0.00

    Out-of-bounds write vulnerability exists in FUJIFILM Business Innovation MFPs. A specially crafted IPP (Internet Printing Protocol) or LPD (Line Printer Daemon) packet may cause a denial-of-service (DoS) condition on an affected MFP. Resetting the MFP is required to recover from…

  • CVE-2021-43774MedMar 3, 2022
    risk 0.32cvss 4.9epss 0.01

    A risky-algorithm issue was discovered on Fujifilm DocuCentre-VI C4471 1.8 devices. An attacker that obtained access to the administrative web interface of a printer (e.g., by using the default credentials) can download the address book file, which contains the list of users…

  • CVE-2025-54551MedAug 20, 2025
    risk 0.28cvss 4.3epss 0.00

    Synapse Mobility 8.0, 8.0.1, 8.0.2, 8.1, and 8.1.1 contain a privilege escalation vulnerability through external control of Web parameter. If exploited, a user of the product may escalate the privilege and access data that the user do not have permission to view by altering the…