CVE-2025-6081: Pass-back attack in Konica Minolta bizhub 227 multifunctional printers
Insufficiently Protected Credentials in LDAP in Konica Minolta bizhub 227 Multifunction printers version GCQ-Y3 or earlier allows an attacker can reconfigure the target device to use an external LDAP service controlled by the attacker. If an LDAP password is set on the target device, the attacker can force the target device to authenticate to the attacker controlled LDAP service. This will allow the attacker to capture the plaintext password of the configured LDAP service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6081?
CVE-2025-6081 has been classified with a medium severity level due to its potential for unauthorized access to credentials.
How do I fix CVE-2025-6081?
To address CVE-2025-6081, ensure that you upgrade the Konica Minolta bizhub 227 to a firmware version newer than GCQ-Y3.
What can attackers do with CVE-2025-6081?
Attackers exploiting CVE-2025-6081 can reconfigure the printer to connect to an unauthorized external LDAP service.
Who is affected by CVE-2025-6081?
CVE-2025-6081 primarily affects users of the Konica Minolta bizhub 227 multifunction printers running firmware version GCQ-Y3 or earlier.
Is my LDAP password secure with CVE-2025-6081?
No, with CVE-2025-6081, the protection of your LDAP password is inadequate, making it vulnerable to exposure.