Notification on the vulnerability for CentreWare Internet Services or Internet Services in FUJIFILM printers
March 6th, 2024
Dear Customers,
Thank you for your continuous support towards FUJIFILM products.
We regret to inform that a potential vulnerability was found in the CentreWare Internet Services or Internet Services in FUJIFILM printers list in the table below.
We recommend customers to check if your printer falls under the list and is affected by those vulnerability. If so, please consider performing the workarounds described below.
Affected products
The models listed below are affected by this vulnerability.
The “Service name” column shows the name of services used in each product.
Product name | Affected firmware versions | Service name |
---|---|---|
DocuPrint P455 d | Any version | CentreWare Internet Services |
DocuPrint M455 df | Any version | CentreWare Internet Services |
DocuPrint C2255 | Any version | CentreWare Internet Services |
DocuCentre-IV C2260 | Any version | CentreWare Internet Services |
DocuCentre-IV C2270 | Any version | CentreWare Internet Services |
DocuCentre-IV C3370 | Any version | CentreWare Internet Services |
DocuCentre-IV C4470 | Any version | CentreWare Internet Services |
DocuCentre-IV C5570 | Any version | CentreWare Internet Services |
ApeosPort-IV C2270 | Any version | CentreWare Internet Services |
ApeosPort-IV C3370 | Any version | CentreWare Internet Services |
ApeosPort-IV C4470 | Any version | CentreWare Internet Services |
ApeosPort-IV C5570 | Any version | CentreWare Internet Services |
ApeosPort-IV C2270 R | Any version | CentreWare Internet Services |
ApeosPort-IV C3370 R | Any version | CentreWare Internet Services |
ApeosPort-IV C4470 R | Any version | CentreWare Internet Services |
ApeosPort-IV C5570 R | Any version | CentreWare Internet Services |
ApeosWide 6050/3030 | Any version | Internet Services |
DocuWide 6057/3037 | Any version | CentreWare Internet Services |
DocuWide 6055 | Any version | CentreWare Internet Services |
DocuWide 3035 | Any version | CentreWare Internet Services |
Details of vulnerability
CentreWare Internet Services or Internet Services are embedded in the above models, and it is possible to operate the devices or change configuration of the devices via web browser. The CentreWare Internet Services have vulnerability against an attack which is called Cross-Site Request Forgery.
Cross-Site Request Forgery (CSRF) is an attack that forces a user to execute unwanted actions on a web application in which they are currently authenticated. With the CentreWare Internet Services or Internet Services, an attacker exploiting the vulnerability may be able to view or change settings and information stored in the device.
Workarounds
We would like to the customers to perform the following procedure to disable the Services to avoid the attacks to the vulnerability.
Please select one of two procedures according to the service name shown in “Service name” column in the Affected Products table above.
How to disable the CentreWare Internet Services
The following describes the configuration procedure for disabling CentreWare Internet Services on the machine.
- Log in as the system administrator
- Display the [Tools] screen
- Press the
button - Enter the system administrator’s user ID with numeric keypad or the keyboard displayed on the screen, and select [Enter].
When a passcode is required, select [Next] and enter the system administrator’s passcode, then select [Enter]. - Select [Tools] on the [Services Home] screen.
- Select [System Settings].
- Disable the Internet Services (HTTP) port on the machine.
- Select [Connectivity & Network Setup].
- Select [Port Settings].
- Select [Internet Services (HTTP)], and then select [Change Settings].
- Select [Port Status], and then select [Change Settings].
- Select [Disabled], and then select [Save].
- Select [Close] repeatedly until the [Tools] screen is displayed
How to disable the Internet Services
The following describes the configuration procedure for disabling Internet Services on the machine.
- Log in as the system administrator
- Tap the user details display area on the upper left of the screen.
- Using the numeric keypad or the displayed keyboard, enter the system administrator's user ID, and tap [Enter].
- Tap [Tools] on the Home screen.
- Disable the Internet Services (HTTP) port on the machine
- Select [Connectivity & Network Setup]
- Select [Port Settings], and then select [Change Settings].
- Select [Port Status], and then select [Change Settings].
- Select [Disabled], and then select [Save].
- Select [Close] repeatedly until the [Tools] screen is displayed
Below mentioned security tips can further help customers to reduce risk of any potential attacks.
- Please use your multi-function or single-function printers within the network protected by firewall etc.
- If access from the Internet is permitted, please consider allowing the access to restricted IP addresses only or use VPN to connect.
Related Information
CVE-2024-27974Acknowledgement
We would like to express gratitude to Junnosuke Kushibiki, Ryu Kuki, Masataka Mizokuchi, Takayuki Sasaki, Katsunari Yoshioka of Yokohama National University for the finding of the vulnerability.
Contact
Please visit the FUJIFILM Business Innovation support website for more details:
https://support-fb.fujifilm.com/