CVE-2019-14309
Summary
| CVE | CVE-2019-14309 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-13 19:15:00 UTC |
| Updated | 2020-03-18 16:14:00 UTC |
| Description | Ricoh SP C250DN 1.05 devices have a fixed password. FTP service credential were found to be hardcoded within the printer firmware. This would allow to an attacker to access and read information stored on the shared FTP folders. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Ricoh | Sp C250dn | - | All | All | All |
| Hardware | Ricoh | Sp C250dn | - | All | All | All |
| Operating System | Ricoh | Sp C250dn Firmware | 1.05 | All | All | All |
| Operating System | Ricoh | Sp C250dn Firmware | 1.05 | All | All | All |
| Hardware | Ricoh | Sp C250sf | - | All | All | All |
| Hardware | Ricoh | Sp C250sf | - | All | All | All |
| Operating System | Ricoh | Sp C250sf Firmware | All | All | All | All |
| Operating System | Ricoh | Sp C250sf Firmware | All | All | All | All |
| Hardware | Ricoh | Sp C252dn | - | All | All | All |
| Hardware | Ricoh | Sp C252dn | - | All | All | All |
| Operating System | Ricoh | Sp C252dn Firmware | All | All | All | All |
| Operating System | Ricoh | Sp C252dn Firmware | All | All | All | All |
| Hardware | Ricoh | Sp C252sf | - | All | All | All |
| Hardware | Ricoh | Sp C252sf | - | All | All | All |
| Operating System | Ricoh | Sp C252sf Firmware | All | All | All | All |
| Operating System | Ricoh | Sp C252sf Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.nccgroup.trust/us/our-research/technical-advisory-multiple-vulnerabilities-i... | MISC | www.nccgroup.trust | Third Party Advisory |
| Support and Downloads | MISC | www.ricoh-usa.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.