CVE-2022-43969

CRITICALCVSS 9.1/10EPSS 0.54%

Last modified

CVE-2022-43969 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Ricoh mp_c4504ex devices with firmware 1.06 mishandle credentials.. EPSS estimates a 0.54% chance of exploitation in the next 30 days.

Description

Ricoh mp_c4504ex devices with firmware 1.06 mishandle credentials.

Metrics

CVSS 3.1
9.1/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

EPSS Probability
0.54%

41.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
RicohMp C307 Firmware<= 1.14
RicohMp C407 Firmware<= 1.14
RicohMp C406 Firmware<= 1.20
RicohMp C306 Firmware<= 1.20
RicohIm Cw2200 Firmware<= 1.01
RicohIm Cw2201 Firmware<= 1.11
RicohMp 402spf Firmware<= 1.12
RicohMp C2003 Smart Operation Panel Firmware<= 1.14
RicohMp C2503 Smart Operation Panel Firmware<= 1.14
RicohMp C2003 Firmware<= 1.17
RicohMp C2503 Firmware<= 1.17
RicohMp C4503 Firmware<= 1.12
RicohMp C5503 Firmware<= 1.12
RicohMp C6003 Firmware<= 1.12
RicohMp C3003 Firmware<= 1.19
RicohMp C3503 Firmware<= 1.19
RicohMp C4503 Smart Operation Panel Firmware<= 2.17
RicohMp C5503 Smart Operation Panel Firmware<= 2.17
RicohMp C6003 Smart Operation Panel Firmware<= 2.17
RicohMp C3003 Smart Operation Panel Firmware<= 2.15
RicohMp C3503 Smart Operation Panel Firmware<= 2.15
RicohMp C2004ex Firmware<= 1.15
RicohMp C2504ex Firmware<= 1.15
RicohMp C4504ex Firmware<= 1.15
RicohMp C5504ex Firmware<= 1.15
RicohMp C6004ex Firmware<= 1.15
RicohMp C3004ex Firmware<= 1.15
RicohMp C3504ex Firmware<= 1.15
RicohPro C5300s Firmware<= 1.07
RicohPro C5310s Firmware<= 1.07
RicohM C2001 Firmware<= 1.01
RicohIm C530f Firmware<= 6.17
RicohIm C530fb Firmware<= 6.17
RicohIm 350f Firmware<= 1.10
RicohIm 350 Firmware<= 1.10
RicohIm 430f Firmware<= 1.10
RicohIm 430fb Firmware<= 1.10
RicohMp 305\+ Firmware<= 1.12
RicohIm 550f Firmware<= 5.02
RicohIm 600f Firmware<= 5.02
RicohIm 600srf Firmware<= 5.02
RicohIm 7000 Firmware<= 2.02
RicohIm 8000 Firmware<= 2.02
RicohIm 9000 Firmware<= 2.02
RicohMp 2555 Firmware<= 1.18
RicohMp 3055 Firmware<= 1.18
RicohMp 3555 Firmware<= 1.18
RicohMp 4055 Firmware<= 1.18
RicohMp 5055 Firmware<= 1.18
RicohMp 6055 Firmware<= 1.18

Showing 50 of 77 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-43969?
Ricoh mp_c4504ex devices with firmware 1.06 mishandle credentials.
How severe is CVE-2022-43969?
CVE-2022-43969 has a CVSS score of 9.1/10 (CRITICAL severity). The EPSS model estimates a 0.54% probability of exploitation in the next 30 days.
How do I fix CVE-2022-43969?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-43969?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST