← Back to browse · API

CVE-2019-14300

Severity
CRITICAL
CVSS
9.8
EPSS
0.0312
Risk score
40.29
CISA KEV
No
PoC
No
Published
2019-08-26
Modified
2024-08-05
First seen
2026-08-07
Aliases
EUVD-2019-5527, GHSA-3RQC-3PFV-6583
Products
n/a:n/a n/a
Sources
euvd EUVD-2019-5527

Description

Several Ricoh printers have multiple buffer overflows parsing HTTP cookie headers, which allow an attacker to cause a denial of service or code execution via crafted requests to the web server. Affected firmware versions depend on the printer models. One affected configuration is cpe:2.3:o:ricoh:sp_c250dn_firmware:-:*:*:*:*:*:*:* up to (including) 1.06 running on cpe:2.3:o:ricoh:sp_c250dn:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252dn:-:*:*:*:*:*:*:*. Another affected configuration is cpe:2.3:o:ricoh:sp_c250sf_firmware:-:*:*:*:*:*:*:* up to (including) 1.12 running on cpe:2.3:o:ricoh:sp_c250sf:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252sf:-:*:*:*:*:*:*:*.

References