Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.8% | — | Ricoh SP 320dn FirmwareRicoh SP 325dnw FirmwareRicoh SP 320sn FirmwareRicoh SP 320sfn Firmware+62 | 15/2/2022 | 17/6/2026 | RICOH Printer series SP products 320DN, SP 325DNw, SP 320SN, SP 320SFN, SP 325SNw, SP 325SFNw, SP 330SN, Aficio SP 3500SF, SP 221S, SP 220SNw, SP 221SNw, SP 221SF, SP 220SFNw, SP 221SFNw v1.06 were discovered to contain a stack buffer overflow in the file /etc/wpa_supplicant.conf. This vulnerability allows attackers… | |
| Modificada | Crítica (9.8) | 1.9% | — | Ricoh SP C250sf FirmwareRicoh SP C252sf FirmwareRicoh SP C250dn FirmwareRicoh SP C252dn Firmware | 13/3/2020 | 17/6/2026 | Ricoh SP C250DN 1.05 devices allow denial of service (issue 2 of 3). Unauthenticated crafted packets to the IPP service will cause a vulnerable device to crash. A memory corruption has been identified in the way of how the embedded device parsed the IPP packets | |
| Modificada | Alta (7.5) | 1.2% | — | Ricoh SP C250sf FirmwareRicoh SP C252sf FirmwareRicoh SP C250dn FirmwareRicoh SP C252dn Firmware | 13/3/2020 | 17/6/2026 | Ricoh SP C250DN 1.05 devices have a fixed password. FTP service credential were found to be hardcoded within the printer firmware. This would allow to an attacker to access and read information stored on the shared FTP folders. | |
| Modificada | Alta (7.5) | 1.3% | — | Ricoh SP C250sf FirmwareRicoh SP C252sf FirmwareRicoh SP C250dn FirmwareRicoh SP C252dn Firmware | 13/3/2020 | 17/6/2026 | Ricoh SP C250DN 1.05 devices allow denial of service (issue 1 of 3). Some Ricoh printers were affected by a wrong LPD service implementation that lead to a denial of service vulnerability. | |
| Modificada | Crítica (9.8) | 1.4% | — | Ricoh SP C250sf FirmwareRicoh SP C252sf FirmwareRicoh SP C250dn FirmwareRicoh SP C252dn Firmware | 13/3/2020 | 17/6/2026 | Ricoh SP C250DN 1.05 devices have an Authentication Method Vulnerable to Brute Force Attacks. Some Ricoh printers did not implement account lockout. Therefore, it was possible to obtain the local account credentials by brute force. | |
| Modificada | Alta (7.5) | 1.4% | — | Ricoh SP C250sf FirmwareRicoh SP C252sf FirmwareRicoh SP C250dn FirmwareRicoh SP C252dn Firmware+44 | 10/1/2020 | 17/6/2026 | Ricoh SP C250DN 1.06 devices have Incorrect Access Control (issue 2 of 2). | |
| Modificada | Alta (8.8) | 0.71% | — | Ricoh SP C250sf FirmwareRicoh SP C252sf FirmwareRicoh SP C250dn FirmwareRicoh SP C252dn Firmware+48 | 10/1/2020 | 17/6/2026 | Ricoh SP C250DN 1.06 devices allow CSRF. | |
| Modificada | Media (6.8) | 0.37% | — | Ricoh SP C250sf FirmwareRicoh SP C252sf FirmwareRicoh SP C250dn FirmwareRicoh SP C252dn Firmware+57 | 10/1/2020 | 17/6/2026 | On Ricoh SP C250DN 1.06 devices, a debug port can be used. | |
| Modificada | Alta (7.5) | 1.4% | — | Ricoh SP C250sf FirmwareRicoh SP C252sf FirmwareRicoh SP C250dn FirmwareRicoh SP C252dn Firmware+48 | 10/1/2020 | 17/6/2026 | Ricoh SP C250DN 1.06 devices have Incorrect Access Control (issue 1 of 2). | |
| Modificada | Crítica (9.8) | 3.0% | — | Ricoh SP C250sf FirmwareRicoh SP C252sf FirmwareRicoh SP C250dn FirmwareRicoh SP C252dn Firmware | 26/8/2019 | 17/6/2026 | Several Ricoh printers have multiple buffer overflows parsing HTTP parameter settings for SNMP, which allow an attacker to cause a denial of service or code execution via crafted requests to the web server. Affected firmware versions depend on the printer models. One affected configuration is… | |
| Modificada | Crítica (9.8) | 3.0% | — | Ricoh SP C250sf FirmwareRicoh SP C252sf FirmwareRicoh SP C250dn FirmwareRicoh SP C252dn Firmware | 26/8/2019 | 17/6/2026 | Several Ricoh printers have multiple buffer overflows parsing HTTP parameter settings for Wi-Fi, mDNS, POP3, SMTP, and notification alerts, which allow an attacker to cause a denial of service or code execution via crafted requests to the web server. Affected firmware versions depend on the printer models. One… | |
| Modificada | Crítica (9.8) | 3.1% | — | Ricoh SP C250sf FirmwareRicoh SP C252sf FirmwareRicoh SP C250dn FirmwareRicoh SP C252dn Firmware | 26/8/2019 | 17/6/2026 | Several Ricoh printers have multiple buffer overflows parsing HTTP cookie headers, which allow an attacker to cause a denial of service or code execution via crafted requests to the web server. Affected firmware versions depend on the printer models. One affected configuration is… | |
| Modificada | Crítica (9.8) | 3.1% | — | Ricoh SP C250sf FirmwareRicoh SP C252sf FirmwareRicoh SP C250dn FirmwareRicoh SP C252dn Firmware | 26/8/2019 | 17/6/2026 | Several Ricoh printers have multiple buffer overflows parsing LPD packets, which allow an attacker to cause a denial of service or code execution via crafted requests to the LPD service. Affected firmware versions depend on the printer models. One affected configuration is… |