7.5
CVE-2019-14309
- EPSS 0.34%
- Veröffentlicht 13.03.2020 19:15:16
- Zuletzt bearbeitet 21.11.2024 04:26:28
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Ricoh SP C250DN 1.05 devices have a fixed password. FTP service credential were found to be hardcoded within the printer firmware. This would allow to an attacker to access and read information stored on the shared FTP folders.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ricoh ≫ Sp C250dn Firmware Version1.05
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.34% | 0.564 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-798 Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.