Security Vulnerabilities - Konica Minolta

Security Vulnerabilities

Multiple vulnerabilities in B/W small multifunction and single-function printers

Dear Customers,

We deeply appreciate your constant patronage to Konica Minolta products.

Multiple security vulnerabilities have been newly identified in the indicated models.

This advisory provides an overview of the issues and the recommended countermeasures.

Please note that, at the time of writing (June 25th, 2025), there have been no confirmed security incidents globally resulting from the exploitation of these vulnerabilities.

Overview of the vulnerabilities

Ref. IDVulnerabilities descriptionReference web site
CVE-2017-9765Stack Buffer Overflow Vulnerabilityhttps://www.cve.org/CVERecord?id=CVE-2017-9765
CVE-2024-2169Infinite Loop of Messages Between Servershttps://www.cve.org/CVERecord?id=CVE-2024-2169
CVE-2024-51977Possibility of information leakage in the printerhttps://www.cve.org/CVERecord?id=CVE-2024-51977
CVE-2024-51978Possibility of Authentication Bypasshttps://www.cve.org/CVERecord?id=CVE-2024-51978
CVE-2024-51979Possible Stack Overflowhttps://www.cve.org/CVERecord?id=CVE-2024-51979
CVE-2024-51980Possibility of a forced TCP connectionhttps://www.cve.org/CVERecord?id=CVE-2024-51980
CVE-2024-51981Possibility of arbitrary HTTP request executionhttps://www.cve.org/CVERecord?id=CVE-2024-51981
CVE-2024-51983External attacks can cause device to crashhttps://www.cve.org/CVERecord?id=CVE-2024-51983
CVE-2024-51984Possibility of information leakage in the printer due to pass-back attackshttps://www.cve.org/CVERecord?id=CVE-2024-51984

Affected Models and the countermeasure firmware

Product nameProgram nameAffected versionFixed version
bizhub 5020iMain-FirmwareU2406280431 (Ver R) or earlierU2412241059 (Ver S) or later
Sub-Firmware1.13 or earlier1.15 or later
bizhub 5000iMain-Firmware1.32 or earlier1.33 or later
Sub-Firmware1.13 or earlier1.15 or later
bizhub 4020iMain-FirmwareU2406280431 (Ver R) or earlierU2412241059 (Ver S) or later
Sub-Firmware1.13 or earlier1.15 or later
bizhub 4000iMain-Firmware1.28 or earlier1.29 or later
Sub-Firmware1.13 or earlier1.15 or later

Remediations

  • Download the Firmware Update Tool from Drivers & Downloads (Software Applications) and upgrade the firmware of your device.
    • Before proceeding, please refer to the attached Firmware Update Procedure guide.
  • If the default administrator password has not yet been changed, it is strongly recommended to update it to a complex and unique password immediately after the update.

Vulnerability Specific Recommendations

Ref. IDMitigations
CVE-2017-9765Disable WSD feature.
CVE-2024-2169Disable TFTP.
CVE-2024-51977Upgrade to the latest firmware (There is no workaround available).
CVE-2024-51978Change the administrator password from the default value.
CVE-2024-51979Change the administrator password from the default value.
CVE-2024-51980Disable WSD feature.
CVE-2024-51981Disable WSD feature.
CVE-2024-51983Disable WSD feature.
CVE-2024-51984Disable WSD feature.

General Security Recommendations

To ensure a secure operating posture for your multifunction devices, and to reduce exposure to the vulnerabilities described in this advisory, Konica Minolta strongly recommends applying the following configuration best practices:

1. Avoid Direct Internet Exposure

Place devices behind firewalls and use private IP addressing.

2. Change Default Passwords

Change default credentials and implement strong passwords for administrative and network functions.

3. Use Strong Passwords for Services

Ensure strong credentials are configured for SMTP, LDAP, and any other integrated services.

4. Disable Unused Services

Turn off unused ports or protocols (specifically WSD & TFTP) to reduce attack surface.

5. Use Secure Protocols

Configure devices to use encrypted communications (e.g., HTTPS, LDAPS, IPPS) where supported.

6. Monitor Device Activity

Regularly review device logs and network traffic for suspicious behavior.

7. Enable Authentication Where Available

Use built-in user authentication features to prevent unauthorised access to device functions.

Enhancing the Security of Products and Services

Konica Minolta considers the security of its products and services to be an important responsibility and will continue to actively respond to incidents and vulnerabilities.

Contact

Should you require further clarification or assistance with implementing the recommended measures or applying the relevant firmware update, please contact your authorised Konica Minolta service representative.