Konicaminolta's vulnerability profile centers on its multifunction printer and imaging device lines, particularly the bizhub series, which occupy a broadly deployed but often overlooked position in office and enterprise networks. Vulnerabilities affecting these devices skew toward serious outcomes, with an elevated share reaching critical severity and a notable tendency toward public exploit availability; the exposure recurs through memory-safety issues such as classic buffer overflows and improper memory-bounds checking, alongside information-disclosure and code-injection weaknesses endemic to embedded web interfaces and firmware. Defenders should prioritize patching and network isolation of affected multifunction devices, which frequently persist as legacy infrastructure with limited visibility; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Konicaminolta over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-7603HIGH Directory traversal vulnerability in Konica Minolta FTP Utility 1.0 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in a RETR command. | Sep 29, 2015 | 7.8 | 76 | NO | YES |
CVE-2015-7768HIGH Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD command. | Oct 9, 2015 | 7.5 | 71 | NO | YES |
CVE-2015-7767HIGH Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long USER command. | Oct 9, 2015 | 7.5 | 30 | NO | YES |
CVE-2020-37069CRITICAL Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the NLST command that allows attackers to overwrite system registers. Attackers can send an oversized buf | Feb 3, 2026 | 9.8 | 29 | NO | NO |
CVE-2020-37068CRITICAL Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the LIST command that allows attackers to overwrite system registers. Attackers can send an oversized buf | Feb 3, 2026 | 9.8 | 29 | NO | NO |
CVE-2022-29588HIGH Konica Minolta bizhub MFP devices before 2022-04-14 use cleartext password storage for the /var/log/nginx/html/ADMINPASS and /etc/shadow files. | May 16, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-29586HIGH Konica Minolta bizhub MFP devices before 2022-04-14 allow a Sandbox Escape. An attacker must attach a keyboard to a USB port, press F12, and then escape from the kiosk mode. | May 16, 2022 | 7.4 | 24 | NO | NO |
CVE-2021-20872MEDIUM Protection mechanism failure vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G00-35 and earlier, bizhub C650i/C550i/C450i G00-B6 and earlier, bizhub C360i/C300i/C250i G | Jan 4, 2022 | 6.8 | 23 | NO | NO |
CVE-2021-20869MEDIUM Exposure of sensitive information to an unauthorized actor vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G00-35 and earlier, bizhub C650i/C550i/C450i G00-B6 and earli | Jan 4, 2022 | 6.5 | 23 | NO | NO |
CVE-2021-20871MEDIUM Exposure of sensitive information to an unauthorized actor vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G00-35 and earlier, bizhub C650i/C550i/C450i G00-B6 and earli | Jan 4, 2022 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Konicaminolta.
Media articles that mention a CVE ID that affects a product developed by Konicaminolta — matched by CVE ID, not by vendor name.