Ricoh SP C250DN 1.05 devices have a fixed password. FTP service credential were found to be hardcoded within the printer firmware. This would allow to an attacker to access and read information stored on the shared FTP folders.
References
Link | Resource |
---|---|
https://www.nccgroup.trust/us/our-research/technical-advisory-multiple-vulnerabilities-in-ricoh-printers/ | Third Party Advisory |
https://www.ricoh-usa.com/en/support-and-download | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
History
No history.
Information
Published : 2020-03-13 19:15
Updated : 2024-02-28 17:47
NVD link : CVE-2019-14309
Mitre link : CVE-2019-14309
CVE.ORG link : CVE-2019-14309
JSON object : View
Products Affected
ricoh
- sp_c252sf
- sp_c252dn_firmware
- sp_c250sf_firmware
- sp_c252dn
- sp_c250dn
- sp_c250dn_firmware
- sp_c250sf
- sp_c252sf_firmware
CWE
CWE-798
Use of Hard-coded Credentials