7.5

CVE-2019-14309

Ricoh SP C250DN 1.05 devices have a fixed password. FTP service credential were found to be hardcoded within the printer firmware. This would allow to an attacker to access and read information stored on the shared FTP folders.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ricoh ≫ Sp C250sf Firmware
   Ricoh ≫ Sp C250sf Version -
Ricoh ≫ Sp C252sf Firmware
   Ricoh ≫ Sp C252sf Version -
Ricoh ≫ Sp C250dn Firmware Version 1.05
   Ricoh ≫ Sp C250dn Version -
Ricoh ≫ Sp C252dn Firmware
   Ricoh ≫ Sp C252dn Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.2% 0.64
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

https://www.ricoh-usa.com/en/support-and-download
Vendor Advisory
https://www.nccgroup.trust/us/our-research/technical-advisory-multiple-vulnerabilities-in-ricoh-printers/
Third Party Advisory