CVE-2019-14308: Buffer Overflow
Several Ricoh printers have multiple buffer overflows parsing LPD packets, which allow an attacker to cause a denial of service or code execution via crafted requests to the LPD service. Affected firmware versions depend on the printer models. One affected configuration is cpe:2.3:o:ricoh:spc250dnfirmware:-::::::: up to (including) 1.06 running on cpe:2.3:o:ricoh:spc250dn:-:::::::, cpe:2.3:o:ricoh:spc252dn:-:::::::. Another affected configuration is cpe:2.3:o:ricoh:spc250sffirmware:-::::::: up to (including) 1.12 running on cpe:2.3:o:ricoh:spc250sf:-:::::::, cpe:2.3:o:ricoh:spc252sf:-:::::::.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-14308?
CVE-2019-14308 is a vulnerability that exists in several Ricoh printers, allowing an attacker to cause a denial of service or execute arbitrary code through crafted requests to the LPD service.
Which Ricoh printers are affected by CVE-2019-14308?
The vulnerability affects Ricoh printers with the following firmware versions: Ricoh Sp C250sf Firmware up to version 1.13, Ricoh Sp C252sf Firmware up to version 1.13, Ricoh Sp C250dn Firmware up to version 1.07, and Ricoh Sp C252dn Firmware up to version 1.07.
How severe is CVE-2019-14308?
CVE-2019-14308 is classified as a critical vulnerability with a severity rating of 9.8.
How can an attacker exploit CVE-2019-14308?
An attacker can exploit CVE-2019-14308 by sending crafted requests to the LPD service on the affected Ricoh printers, causing a denial of service or executing arbitrary code.
How can I protect my Ricoh printer from CVE-2019-14308?
To protect your Ricoh printer from CVE-2019-14308, update the firmware to the latest version available from the Ricoh support and download page.