CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Sp_4520dn_firmware, Sp_4520dn, Sp_4510dn_firmware, Sp_4510dn, Sp_c250sf_firmware, Sp_c250sf, Sp_c252sf_firmware, Sp_c252sf, Sp_c250dn_firmware, Sp_c250dn
2020-03-18
N/A
7.5 HIGH
Ricoh SP C250DN 1.05 devices have a fixed password. FTP service credential were found to be hardcoded within the printer firmware. This would allow to an attacker to access and read information stored on the shared FTP folders.
Sp_4520dn_firmware, Sp_4520dn, Sp_4510dn_firmware, Sp_4510dn, Sp_c250sf_firmware, Sp_c250sf, Sp_c252sf_firmware, Sp_c252sf, Sp_c250dn_firmware, Sp_c250dn
2019-09-13
N/A
9.8 CRITICAL
Several Ricoh printers have multiple buffer overflows parsing LPD packets, which allow an attacker to cause a denial of service or code execution via crafted requests to the LPD service. Affected firmware versions depend on the printer models. One affected configuration is cpe:2.3:o:ricoh:sp_c250dn_firmware:-:*:*:*:*:*:*:* up to (including) 1.06 running on cpe:2.3:o:ricoh:sp_c250dn:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252dn:-:*:*:*:*:*:*:*. Another affected configuration is cpe:2.3:o:ricoh:sp_c250sf_firmware:-:*:*:*:*:*:*:* up to (including) 1.12 running on cpe:2.3:o:ricoh:sp_c250sf:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252sf:-:*:*:*:*:*:*:*.
Sp_4520dn_firmware, Sp_4520dn, Sp_4510dn_firmware, Sp_4510dn, Sp_c250sf_firmware, Sp_c250sf, Sp_c252sf_firmware, Sp_c252sf, Sp_c250dn_firmware, Sp_c250dn
2019-09-13
N/A
9.8 CRITICAL
Several Ricoh printers have multiple buffer overflows parsing HTTP parameter settings for SNMP, which allow an attacker to cause a denial of service or code execution via crafted requests to the web server. Affected firmware versions depend on the printer models. One affected configuration is cpe:2.3:o:ricoh:sp_c250dn_firmware:-:*:*:*:*:*:*:* up to (including) 1.06 running on cpe:2.3:o:ricoh:sp_c250dn:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252dn:-:*:*:*:*:*:*:*. Another affected configuration is cpe:2.3:o:ricoh:sp_c250sf_firmware:-:*:*:*:*:*:*:* up to (including) 1.12 running on cpe:2.3:o:ricoh:sp_c250sf:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252sf:-:*:*:*:*:*:*:*.
Sp_4520dn_firmware, Sp_4520dn, Sp_4510dn_firmware, Sp_4510dn, Sp_c250sf_firmware, Sp_c250sf, Sp_c252sf_firmware, Sp_c252sf, Sp_c250dn_firmware, Sp_c250dn
2023-01-31
N/A
7.5 HIGH
Ricoh SP C250DN 1.06 devices have Incorrect Access Control (issue 2 of 2).
Sp_4520dn_firmware, Sp_4520dn, Sp_4510dn_firmware, Sp_4510dn, Sp_c250sf_firmware, Sp_c250sf, Sp_c252sf_firmware, Sp_c252sf, Sp_c250dn_firmware, Sp_c250dn
2019-09-13
N/A
9.8 CRITICAL
Several Ricoh printers have multiple buffer overflows parsing HTTP parameter settings for Wi-Fi, mDNS, POP3, SMTP, and notification alerts, which allow an attacker to cause a denial of service or code execution via crafted requests to the web server. Affected firmware versions depend on the printer models. One affected configuration is cpe:2.3:o:ricoh:sp_c250dn_firmware:-:*:*:*:*:*:*:* up to (including) 1.06 running on cpe:2.3:o:ricoh:sp_c250dn:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252dn:-:*:*:*:*:*:*:*. Another affected configuration is cpe:2.3:o:ricoh:sp_c250sf_firmware:-:*:*:*:*:*:*:* up to (including) 1.12 running on cpe:2.3:o:ricoh:sp_c250sf:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252sf:-:*:*:*:*:*:*:*.
Sp_4520dn_firmware, Sp_4520dn, Sp_4510dn_firmware, Sp_4510dn, Sp_c250sf_firmware, Sp_c250sf, Sp_c252sf_firmware, Sp_c252sf, Sp_c250dn_firmware, Sp_c250dn
2023-02-01
N/A
8.8 HIGH
Ricoh SP C250DN 1.06 devices allow CSRF.
Sp_4520dn_firmware, Sp_4520dn, Sp_4510dn_firmware, Sp_4510dn, Sp_c250sf_firmware, Sp_c250sf, Sp_c252sf_firmware, Sp_c252sf, Sp_c250dn_firmware, Sp_c250dn
2020-08-24
N/A
7.5 HIGH
Ricoh SP C250DN 1.05 devices allow denial of service (issue 1 of 3). Some Ricoh printers were affected by a wrong LPD service implementation that lead to a denial of service vulnerability.
Sp_4520dn_firmware, Sp_4520dn, Sp_4510dn_firmware, Sp_4510dn, Sp_c250sf_firmware, Sp_c250sf, Sp_c252sf_firmware, Sp_c252sf, Sp_c250dn_firmware, Sp_c250dn
2023-02-01
N/A
6.8 MEDIUM
On Ricoh SP C250DN 1.06 devices, a debug port can be used.
Sp_4520dn_firmware, Sp_4520dn, Sp_4510dn_firmware, Sp_4510dn, Sp_c250sf_firmware, Sp_c250sf, Sp_c252sf_firmware, Sp_c252sf, Sp_c250dn_firmware, Sp_c250dn
2023-02-01
N/A
7.5 HIGH
Ricoh SP C250DN 1.06 devices have Incorrect Access Control (issue 1 of 2).
Sp_4520dn_firmware, Sp_4520dn, Sp_4510dn_firmware, Sp_4510dn, Sp_c250sf_firmware, Sp_c250sf, Sp_c252sf_firmware, Sp_c252sf, Sp_c250dn_firmware, Sp_c250dn
2019-09-13
N/A
9.8 CRITICAL
Several Ricoh printers have multiple buffer overflows parsing HTTP cookie headers, which allow an attacker to cause a denial of service or code execution via crafted requests to the web server. Affected firmware versions depend on the printer models. One affected configuration is cpe:2.3:o:ricoh:sp_c250dn_firmware:-:*:*:*:*:*:*:* up to (including) 1.06 running on cpe:2.3:o:ricoh:sp_c250dn:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252dn:-:*:*:*:*:*:*:*. Another affected configuration is cpe:2.3:o:ricoh:sp_c250sf_firmware:-:*:*:*:*:*:*:* up to (including) 1.12 running on cpe:2.3:o:ricoh:sp_c250sf:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252sf:-:*:*:*:*:*:*:*.
