Notice of security investigation: Vulnerability (CVE-2022-43969) towards scanner or FAX-installed Ricoh products that may cause folder user password breach
First published: 07:00 pm on December 26, 2022 (2022-12-26T17:00:00+09:00)
Ricoh understands the importance of security and is committed to managing its products and services with the most advanced security technologies possible for its customers worldwide.
Ricoh is aware of the reported "Threat of folder user password breach"(CVE-2022-43969) that affects certain products and services that Ricoh develops, manufactures, and offers.
The user password for the folder, that is saved to a device with data transmission functionality, may be breached via a malicious ftp server by changing data transmission setting.
List 1 below shows the affected products and services. Ricoh offers measures detailed in the hyperlinked pages in the list.
Products and services not mentioned in List 1 are currently under security investigation. Please note that this page will be updated if there is change in status.
Vulnerability Information ID | ricoh-2022-000002 |
Version | 1.00E |
CVE ID(CWE ID) | CVE-2022-43969 ( CWE-255 ) |
CVSSv3 score | 9.1 CRITICAL |
List 1: Ricoh products and services affected by this vulnerability
Contact
Please contact your local Ricoh representative or dealer if you have any queries.
Acknowledgement:
Ricoh would like to thank Wouter Arts and Geert Braakhekke of WTH Security for reporting this vulnerability.
History:
2022-12-26T17:00:00+09:00 : 1.00E Initial public release
News & Events
Keep you up to date with Ricoh
-
23 Jan
Ricoh ranked top computers and peripherals manufacturing company and 51st among the 2025 Global 100 Most Sustainable Corporations
-
16 Jan
Ricoh named a Leader in 2024 IDC MarketScape for Worldwide Cloud Managed Print and Document Services Hardcopy
-
06 Jan
Ricoh named third largest in audio visual integrator list by SCN for two consecutive years
-
24 Dec
Ricoh included in the Dow Jones Sustainability World Index for five consecutive years