VYPR
Unrated severityNVD Advisory· Published Jan 10, 2020· Updated Aug 5, 2024

CVE-2019-14306

CVE-2019-14306

Description

Ricoh SP C250DN 1.06 devices have Incorrect Access Control (issue 2 of 2).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Ricoh SP C250DN 1.06 devices have an improper authentication vulnerability allowing an adjacent attacker to obtain device settings information.

Vulnerability

The Ricoh SP C250DN printer, firmware version 1.06, contains an improper authentication vulnerability (CWE-287) classified as CVE-2019-14306. The issue resides in the device's management interface, where the debugging web page does not properly authenticate users before granting access to sensitive configuration data. An adjacent attacker can access this page without any credentials, leading to information disclosure [1].

Exploitation

An attacker needs network adjacency to the affected device (AV:A) and no authentication (PR:N). No user interaction is required. The attacker can directly browse to the debugging web page exposed on the device's network interface, which fails to enforce authentication checks, thereby allowing retrieval of device settings information [1].

Impact

Successful exploitation results in unauthorized disclosure of the device's settings information. The impact is limited to confidentiality (NIST: C), with no effect on integrity or availability. The CVSS v3 base score is 6.5 (medium), and the CVSS v2 score is 3.3 (low) [1].

Mitigation

Ricoh has released firmware updates to address the vulnerability. Users should apply the appropriate firmware update for the Ricoh SP C250DN as provided in the vendor's advisory [1]. No workarounds are mentioned in available references.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.