Fujifilm's vulnerability footprint centers on a broad lineup of multifunction office devices and their firmware, including the Apeos and ApeosPort printer and copier series widely deployed in enterprise and small-business environments. Vulnerabilities affecting these devices skew toward serious outcomes and recur through authentication and access-control weakness classes—including improper access control, missing authentication for critical functions, and insufficiently protected credentials—that expose device administration and document handling to unauthorized access. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fujifilm over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10950CRITICAL Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X provide insecure telnet services that lack authentic | Apr 30, 2019 | 9.8 | 31 | NO | NO |
CVE-2022-26320CRITICAL The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices throu | Mar 14, 2022 | 9.1 | 27 | NO | NO |
CVE-2019-10948HIGH Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X are susceptible to a denial-of-service condition as | Apr 30, 2019 | 7.5 | 25 | NO | NO |
CVE-2022-43460HIGH Driver Distributor v2.2.3.1 and earlier contains a vulnerability where passwords are stored in a recoverable format. If an attacker obtains a configuration file of Driver Distribut | Feb 13, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-29984HIGH Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an | Jul 11, 2023 | 7.5 | 22 | NO | NO |
CVE-2017-10850HIGH Untrusted search path vulnerability in Installers of ART EX Driver for ApeosPort-VI C7771/C6671/C5571/C4471/C3371/C2271, DocuCentre-VI C7771/C6671/C5571/C4471/C3371/C2271 (Timestam | Sep 1, 2017 | 7.8 | 20 | NO | NO |
CVE-2021-43774MEDIUM A risky-algorithm issue was discovered on Fujifilm DocuCentre-VI C4471 1.8 devices. An attacker that obtained access to the administrative web interface of a printer (e.g., by usin | Mar 3, 2022 | 4.9 | 19 | NO | NO |
CVE-2023-46327MEDIUM Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a facility to export the contents of their Address Book with enc | Nov 2, 2023 | 5.9 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fujifilm.
Media articles that mention a CVE ID that affects a product developed by Fujifilm — matched by CVE ID, not by vendor name.