CVE-2019-14300
Summary
| CVE | CVE-2019-14300 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-26 15:15:00 UTC |
| Updated | 2019-09-13 05:15:00 UTC |
| Description | Several Ricoh printers have multiple buffer overflows parsing HTTP cookie headers, which allow an attacker to cause a denial of service or code execution via crafted requests to the web server. Affected firmware versions depend on the printer models. One affected configuration is cpe:2.3:o:ricoh:sp_c250dn_firmware:-:*:*:*:*:*:*:* up to (including) 1.06 running on cpe:2.3:o:ricoh:sp_c250dn:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252dn:-:*:*:*:*:*:*:*. Another affected configuration is cpe:2.3:o:ricoh:sp_c250sf_firmware:-:*:*:*:*:*:*:* up to (including) 1.12 running on cpe:2.3:o:ricoh:sp_c250sf:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252sf:-:*:*:*:*:*:*:*. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Ricoh | Sp C250dn | - | All | All | All |
| Hardware | Ricoh | Sp C250dn | - | All | All | All |
| Operating System | Ricoh | Sp C250dn Firmware | All | All | All | All |
| Operating System | Ricoh | Sp C250dn Firmware | All | All | All | All |
| Hardware | Ricoh | Sp C250sf | - | All | All | All |
| Hardware | Ricoh | Sp C250sf | - | All | All | All |
| Operating System | Ricoh | Sp C250sf Firmware | All | All | All | All |
| Operating System | Ricoh | Sp C250sf Firmware | All | All | All | All |
| Hardware | Ricoh | Sp C252dn | - | All | All | All |
| Hardware | Ricoh | Sp C252dn | - | All | All | All |
| Operating System | Ricoh | Sp C252dn Firmware | All | All | All | All |
| Operating System | Ricoh | Sp C252dn Firmware | All | All | All | All |
| Hardware | Ricoh | Sp C252sf | - | All | All | All |
| Hardware | Ricoh | Sp C252sf | - | All | All | All |
| Operating System | Ricoh | Sp C252sf Firmware | All | All | All | All |
| Operating System | Ricoh | Sp C252sf Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| UPDATE: Potential security vulnerabilities in some of Ricoh's printers and Multifunction Printers (MFPs) | Global | Ricoh | MISC | www.ricoh.com | Vendor Advisory |
| JVN#11708203: Multiple buffer overflow vulnerabilities in multiple Ricoh printers and Multifunction Printers (MFPs) | JVN | jvn.jp | |
| Support and Downloads | MISC | www.ricoh-usa.com | Product |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.