The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with Fermat's factorization method. This allows efficient calculation of private RSA keys from the public key of a TLS certificate.
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
Link | Tags |
---|---|
https://global.canon/en/support/security/index.html | third party advisory |
https://fermatattack.secvuln.info | third party advisory |
https://www.fujifilm.com/fbglobal/eng/company/news/notice/2022/0302_rsakey_announce.html | mitigation third party advisory |
https://www.rambus.com/security/response-center/advisories/rmbs-2021-01/ | |
https://web.archive.org/web/20220922042721/https://safezoneswupdate.com/ | |
https://safezoneswupdate.com |