Cross-Site Request Forgery Vulnerability in Ricoh SP C250DN Printer
CVE-2019-14304

8.8HIGH

Key Information:

Vendor

Ricoh

Vendor
CVE Published:
10 January 2020

What is CVE-2019-14304?

The Ricoh SP C250DN printer, specifically version 1.06, is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability. This flaw can allow an attacker to perform unauthorized actions on behalf of an authenticated user without their consent. Exploiting this vulnerability may lead to potentially harmful alterations in the printer's settings or unauthorized access to sensitive data. Users are advised to patch their devices to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.