CVE-2018-18006: Critical severity ricoh myprint vulnerability
Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any externally disclosed myPrint WSDL API, as demonstrated by discovering API secrets of related Google cloud printers, encrypted passwords of mail servers, and names of printed files.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-18006?
CVE-2018-18006 refers to the vulnerability in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android, which allows unauthorized access to sensitive information.
What is the severity of CVE-2018-18006?
CVE-2018-18006 has a severity rating of 9.8, indicating a critical vulnerability.
What is the affected software?
The affected software is Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android.
How does CVE-2018-18006 give access to sensitive information?
CVE-2018-18006 exposes hardcoded credentials in the Ricoh myPrint application, allowing unauthorized access to API secrets, encrypted passwords of mail servers, and names of printed files.
Are there any public references for CVE-2018-18006?
Yes, you can find more information about CVE-2018-18006 at the following references: [Packet Storm Security](http://packetstormsecurity.com/files/150399/Ricoh-myPrint-Hardcoded-Credentials-Information-Disclosure.html) and [Full Disclosure](http://seclists.org/fulldisclosure/2018/Nov/46).