CVE-2018-16187
Summary
| CVE | CVE-2018-16187 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-01-09 23:29:00 UTC |
| Updated | 2019-02-08 17:15:00 UTC |
| Description | The RICOH Interactive Whiteboard D2200 V1.3 to V2.2, D5500 V1.3 to V2.2, D5510 V1.3 to V2.2, the display versions with RICOH Interactive Whiteboard Controller Type1 V1.3 to V2.2 attached (D5520, D6500, D6510, D7500, D8400), and the display versions with RICOH Interactive Whiteboard Controller Type2 V3.0 to V3.1.10137.0 attached (D5520, D6510, D7500, D8400) does not verify its server certificates, which allows man-in-the-middle attackers to eversdrop on encrypted communication. |
Risk And Classification
Problem Types: CWE-295
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Ricoh | D2200 | - | All | All | All |
| Hardware | Ricoh | D2200 | - | All | All | All |
| Operating System | Ricoh | D2200 Firmware | All | All | All | All |
| Hardware | Ricoh | D5500 | - | All | All | All |
| Hardware | Ricoh | D5500 | - | All | All | All |
| Operating System | Ricoh | D5500 Firmware | All | All | All | All |
| Hardware | Ricoh | D5510 | - | All | All | All |
| Hardware | Ricoh | D5510 | - | All | All | All |
| Operating System | Ricoh | D5510 Firmware | All | All | All | All |
| Hardware | Ricoh | D5520 | - | All | All | All |
| Hardware | Ricoh | D5520 | - | All | All | All |
| Operating System | Ricoh | D5520 Firmware | All | All | All | All |
| Operating System | Ricoh | D5520 Firmware | All | All | All | All |
| Hardware | Ricoh | D6500 | - | All | All | All |
| Hardware | Ricoh | D6500 | - | All | All | All |
| Operating System | Ricoh | D6500 Firmware | All | All | All | All |
| Hardware | Ricoh | D6510 | - | All | All | All |
| Hardware | Ricoh | D6510 | - | All | All | All |
| Operating System | Ricoh | D6510 Firmware | All | All | All | All |
| Operating System | Ricoh | D6510 Firmware | All | All | All | All |
| Hardware | Ricoh | D7500 | - | All | All | All |
| Hardware | Ricoh | D7500 | - | All | All | All |
| Operating System | Ricoh | D7500 Firmware | All | All | All | All |
| Operating System | Ricoh | D7500 Firmware | All | All | All | All |
| Hardware | Ricoh | D8400 | - | All | All | All |
| Hardware | Ricoh | D8400 | - | All | All | All |
| Operating System | Ricoh | D8400 Firmware | All | All | All | All |
| Operating System | Ricoh | D8400 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| JVN#55263945: Multiple vulnerabilities in RICOH Interactive Whiteboard | JVN | jvn.jp | Third Party Advisory |
| Important: New firmware released for RICOH Interactive Whiteboard | Global | Ricoh | MISC | www.ricoh.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.