9.8

CVE-2019-14299

Ricoh SP C250DN 1.05 devices have an Authentication Method Vulnerable to Brute Force Attacks. Some Ricoh printers did not implement account lockout. Therefore, it was possible to obtain the local account credentials by brute force.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ricoh ≫ Sp C250sf Firmware
   Ricoh ≫ Sp C250sf Version -
Ricoh ≫ Sp C252sf Firmware
   Ricoh ≫ Sp C252sf Version -
Ricoh ≫ Sp C250dn Firmware Version 1.05
   Ricoh ≫ Sp C250dn Version -
Ricoh ≫ Sp C252dn Firmware
   Ricoh ≫ Sp C252dn Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.41% 0.691
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-307 Improper Restriction of Excessive Authentication Attempts

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

https://www.ricoh-usa.com/en/support-and-download
Vendor Advisory
https://www.nccgroup.trust/us/our-research/technical-advisory-multiple-vulnerabilities-in-ricoh-printers/
Third Party Advisory