8.4
CVE-2023-30759
- EPSS 0.14%
- Veröffentlicht 19.06.2023 05:15:09
- Zuletzt bearbeitet 12.12.2024 21:15:07
- CVE-Watchlists
- Unerledigt
The driver installation package created by Printer Driver Packager NX v1.0.02 to v1.1.25 fails to detect its modification and may spawn an unexpected process with the administrative privilege. If a non-administrative user modifies the driver installation package and runs it on the target PC, an arbitrary program may be executed with the administrative privilege.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ricoh ≫ Printer Driver Packager Nx Version >= 1.0.02 < 1.1.26
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.04 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| CISA-ADP | 8.4 | 2.5 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-345 Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
https://jvn.jp/en/vu/JVNVU92207133/
https://www.ricoh.com/products/security/vulnerabilities/adv?id=ricoh-prod000048-2023-000001
https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2023-000001