[Japanese] | |
JVNDB-2024-000117 | |
Stack-based buffer overflow vulnerability in multiple Ricoh laser printers and MFPs which implement Web Image Monitor | |
Overview | |
Web Image Monitor provided by Ricoh Company, Ltd. is an web server included and runs in Ricoh laser printers and MFPs (multifunction printers). Web Image Monitor contains a stack-based buffer overflow vulnerability (CWE-121) due to inappropriate parsing process of HTTP request. | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 9.8 (Critical) [IPA Score]
| |
Affected Products | |
| |
Ricoh Co., Ltd | |
As for the details of affected product names and versions, refer to the information provided by the developer. | |
Impact | |
Receiving a specially crafted request created and sent by an attacker may lead to arbitrary code execution and/or a denial-of-service (DoS) condition. | |
Solution | |
[Update Web Image Monitor] | |
Vendor Information | |
Ricoh Co., Ltd | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2024/10/31 |
Date First Published | 2024/10/31 |
Date Last Updated | 2024/10/31 |