SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-33945

RICOH Printer series SP products 320DN, SP 325DNw, SP 320SN, SP 320SFN, SP 325SNw, SP 325SFNw, SP 330SN, Aficio SP 3500SF, SP 221S, SP 220SNw, SP 221SNw, SP 221SF, SP 220SFNw, SP 221SFNw v1.06 were discovered to contain a stack buffer overflow in the…

CRITICAL 9.8EPSS 1.85%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.85%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

RICOH Printer series SP products 320DN, SP 325DNw, SP 320SN, SP 320SFN, SP 325SNw, SP 325SFNw, SP 330SN, Aficio SP 3500SF, SP 221S, SP 220SNw, SP 221SNw, SP 221SF, SP 220SFNw, SP 221SFNw v1.06 were discovered to contain a stack buffer overflow in the file /etc/wpa_supplicant.conf. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.85% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-787
Affected
ricoh/sp 320dn firmware · ricoh/sp 325dnw firmware · ricoh/sp 320sn firmware · ricoh/sp 320sfn firmware · ricoh/sp 325snw firmware · ricoh/sp 325sfnw firmware · ricoh/sp 330sn firmware · ricoh/aficio sp 3500sf firmware · ricoh/sp 221s firmware · ricoh/sp 220snw firmware · ricoh/sp 221snw firmware · ricoh/sp 221sf firmware · ricoh/sp 220sfnw firmware · ricoh/sp 221sfnw firmware · ricoh/m c2000 firmware · ricoh/m c250fwb firmware · ricoh/m c250fw firmware · ricoh/sp c260sfnw firmware · ricoh/sp c262sfnw firmware · ricoh/sp c261sfnw firmware · +40 more
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.