CVE-2022-36403: High severity device software manager vulnerability
Published Sep 8, 2022
·Updated
Untrusted search path vulnerability in the installer of Device Software Manager prior to Ver.2.20.3.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Affected Software
1 affected component
Ricoh Device Software Manager<2.20.3.0
Event History
Sep 8, 2022
CVE Published
via MITRE·07:10 AM
Data Sourced
via MITRE·07:10 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-36403.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Untrusted search path vulnerability in the installer of Device Software Manager prior to Ver.2.20.3.'
3
What is the severity of CVE-2022-36403?
The severity of CVE-2022-36403 is high with a score of 7.8.
4
How does this vulnerability affect the affected software?
This vulnerability affects Ricoh Device Software Manager prior to Ver.2.20.3.0.
5
How can an attacker exploit this vulnerability?
An attacker can gain privileges by using a Trojan horse DLL in an unspecified directory.