Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Giuliano Fasto

Researcher fromForegenix
#49768of 53,633
4.9Total CVSS
Vulnerabilities · 1
PT-2022-11909
4.9
2022-03-03
Fujifilm · Fujifilm Docucentre-Vi C4471 · CVE-2021-43774
**Name of the Vulnerable Software and Affected Versions** Fujifilm DocuCentre-VI C4471 version 1.8 **Description** A risky-algorithm issue allows an attacker with access to the administrative web interface to download the address book file, containing a list of users and their encrypted passwords. The passwords are protected by a weak cipher, such as ROT13, which can be easily decrypted to obtain valid domain or FTP usernames and passwords. **Recommendations** For Fujifilm DocuCentre-VI C4471 version 1.8, consider changing the default credentials and restricting access to the administrative web interface to minimize the risk of exploitation. Additionally, avoid using weak ciphers like ROT13 for password protection until a more secure alternative is implemented. At the moment, there is no information about a newer version that contains a fix for this vulnerability.