CVE-2022-37406: XSS
Published Dec 7, 2022
·Updated
Cross-site scripting vulnerability in Aficio SP 4210N firmware versions prior to Web Support 1.05 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.
Affected Software
4 affected components
Ricoh Aficio Sp 4210n Firmware<1.05
Ricoh Aficio Sp 4210n
All of the following
Ricoh Aficio Sp 4210n Firmware<1.05
Ricoh Aficio Sp 4210n
Event History
Dec 7, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-37406?
The severity of CVE-2022-37406 is medium with a CVSS score of 4.8.
2
How does CVE-2022-37406 affect Ricoh Aficio SP 4210N firmware?
CVE-2022-37406 affects Ricoh Aficio SP 4210N firmware versions prior to Web Support 1.05.
3
What is the impact of CVE-2022-37406?
CVE-2022-37406 allows a remote authenticated attacker with administrative privilege to inject an arbitrary script.
4
Is Ricoh Aficio SP 4210N vulnerable to CVE-2022-37406?
Yes, Ricoh Aficio SP 4210N firmware versions prior to Web Support 1.05 are vulnerable to CVE-2022-37406.
5
How can I fix CVE-2022-37406?
To fix CVE-2022-37406, update Ricoh Aficio SP 4210N firmware to Web Support 1.05 or later.