9.8
CVSSv3

CVE-2018-18006

Published: 14/12/2018 Updated: 03/01/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any externally disclosed myPrint WSDL API, as demonstrated by discovering API secrets of related Google cloud printers, encrypted passwords of mail servers, and names of printed files.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ricoh myprint 2.2.7

ricoh myprint 2.9.2.4

Exploits

Ricoh myPrint suffers from hardcoded application credential and information disclosure vulnerabilities The myPrint windows client version 2924 and myPrint android client version 227 are both affected ...