« Volver al listado

CVE-2024-37387

Estado: AplazadaMedia (4)—

Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, files in the PC where the product is installed may be altered.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-37387",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-37387",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-06-21T14:51:30.816250Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.5
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "RICOH COMPANY, LTD.",
          "product": "Ricoh Streamline NX PC Client",
          "versions": [
            {
              "status": "affected",
              "version": "ver.3.2.1.19"
            },
            {
              "status": "affected",
              "version": " ver.3.3.1.3"
            },
            {
              "status": "affected",
              "version": " ver.3.3.2.201"
            },
            {
              "status": "affected",
              "version": " ver.3.4.3.1"
            },
            {
              "status": "affected",
              "version": " ver.3.5.1.201 (ver.3.5.1.200op1)"
            },
            {
              "status": "affected",
              "version": " ver.3.6.100.53"
            },
            {
              "status": "affected",
              "version": " and ver.3.6.2.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2024-06-19T07:15:46.647",
  "references": [
    {
      "url": "https://jvn.jp/en/jp/JVN00442488/",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2024-000007",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN00442488/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2024-000007",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-676"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, files in the PC where the product is installed may be altered."
    },
    {
      "lang": "es",
      "value": "Existe un problema de uso de funciones potencialmente peligrosas en Ricoh Streamline NX PC Client. Si se aprovecha esta vulnerabilidad, es posible que se modifiquen los archivos del PC donde está instalado el producto."
    }
  ],
  "lastModified": "2026-06-17T07:38:16.210",
  "sourceIdentifier": "vultures@jpcert.or.jp"
}