PT-2020-9550 · Ricoh · Ricoh Sp C250Dn
Published
2020-03-13
·
Updated
2020-03-18
·
CVE-2019-14309
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Ricoh SP C250DN version 1.05
Description:
The issue concerns a fixed password in the device's FTP service credentials, which are hardcoded within the printer firmware. This would allow an attacker to access and read information stored on the shared FTP folders.
Recommendations:
For version 1.05, consider changing the hardcoded FTP service credentials to unique and secure passwords to prevent unauthorized access. As a temporary workaround, restrict access to the FTP service until a patch or update is available.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ricoh Sp C250Dn