Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-14305

Опубликовано: 26 авг. 2019
Источник: nvd
CVSS3: 8.8
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

Several Ricoh printers have multiple buffer overflows parsing HTTP parameter settings for Wi-Fi, mDNS, POP3, SMTP, and notification alerts, which allow an attacker to cause a denial of service or code execution via crafted requests to the web server. Affected firmware versions depend on the printer models. One affected configuration is cpe:2.3:o:ricoh:sp_c250dn_firmware:-:::::::* up to (including) 1.06 running on cpe:2.3:o:ricoh:sp_c250dn:-:::::::, cpe:2.3:o:ricoh:sp_c252dn:-:::::::. Another affected configuration is cpe:2.3:o:ricoh:sp_c250sf_firmware:-:::::::* up to (including) 1.12 running on cpe:2.3:o:ricoh:sp_c250sf:-:::::::, cpe:2.3:o:ricoh:sp_c252sf:-:::::::.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:ricoh:sp_c250sf_firmware:*:*:*:*:*:*:*:*
Версия до 1.13 (исключая)
cpe:2.3:h:ricoh:sp_c250sf:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:ricoh:sp_c252sf_firmware:*:*:*:*:*:*:*:*
Версия до 1.13 (исключая)
cpe:2.3:h:ricoh:sp_c252sf:-:*:*:*:*:*:*:*
Конфигурация 3

Одновременно

cpe:2.3:o:ricoh:sp_c250dn_firmware:*:*:*:*:*:*:*:*
Версия до 1.07 (исключая)
cpe:2.3:h:ricoh:sp_c250dn:-:*:*:*:*:*:*:*
Конфигурация 4

Одновременно

cpe:2.3:o:ricoh:sp_c252dn_firmware:*:*:*:*:*:*:*:*
Версия до 1.07 (исключая)
cpe:2.3:h:ricoh:sp_c252dn:-:*:*:*:*:*:*:*

EPSS

Процентиль: 77%
0.01085
Низкий

8.8 High

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

Several Ricoh printers have multiple buffer overflows parsing HTTP parameter settings for Wi-Fi, mDNS, POP3, SMTP, and notification alerts, which allow an attacker to cause a denial of service or code execution via crafted requests to the web server. Affected firmware versions depend on the printer models. One affected congiguration is cpe:2.3:o:ricoh:sp_c250dn_firmware:-:*:*:*:*:*:*:* up to (including) 1.06 running on cpe:2.3:o:ricoh:sp_c250dn:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252dn:-:*:*:*:*:*:*:*. Another affected congiguration is cpe:2.3:o:ricoh:sp_c250sf_firmware:-:*:*:*:*:*:*:* up to (including) 1.12 running on cpe:2.3:o:ricoh:sp_c250sf:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252sf:-:*:*:*:*:*:*:*.

EPSS

Процентиль: 77%
0.01085
Низкий

8.8 High

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-119