CVE-2019-14308
Description
Several Ricoh printers have multiple buffer overflows parsing LPD packets, which allow an attacker to cause a denial of service or code execution via crafted requests to the LPD service. Affected firmware versions depend on the printer models. One affected configuration is cpe:2.3:o:ricoh:sp_c250dn_firmware:-:*:*:*:*:*:*:* up to (including) 1.06 running on cpe:2.3:o:ricoh:sp_c250dn:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252dn:-:*:*:*:*:*:*:*. Another affected configuration is cpe:2.3:o:ricoh:sp_c250sf_firmware:-:*:*:*:*:*:*:* up to (including) 1.12 running on cpe:2.3:o:ricoh:sp_c250sf:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252sf:-:*:*:*:*:*:*:*.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A buffer overflow in Ricoh printers' LPD packet parsing allows unauthenticated remote attackers to cause denial of service or execute arbitrary code.
Vulnerability
Several Ricoh printers and Multifunction Printers (MFPs) contain a buffer overflow vulnerability in the parsing of LPD packets (CWE-119), tracked as CVE-2019-14308. The affected firmware versions depend on the printer model; for example, the Ricoh SP C250dn firmware up to version 1.06 and the Ricoh SP C250sf firmware up to version 1.12 are vulnerable [1]. The flaw is triggered when the device processes a specially crafted LPD packet [1].
Exploitation
An attacker can exploit this vulnerability remotely over the network without requiring any authentication [1]. The only prerequisite is that the target printer's LPD service is accessible. By sending a crafted LPD packet, the attacker can trigger a buffer overflow [1].
Impact
Successful exploitation of this buffer overflow can allow a remote attacker to cause a denial-of-service (DoS) condition or to execute arbitrary code on the affected device [1]. The CVSS v3 base score is 9.8, indicating critical severity [1].
Mitigation
Ricoh has released firmware updates to address this vulnerability [1]. Users should apply the appropriate firmware update according to the information provided by the developer [1]. As of the publication date, no workaround has been publicly disclosed [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
5- Ricoh/printersdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- jvn.jp/en/jp/JVN11708203/index.htmlmitrethird-party-advisoryx_refsource_JVN
- www.ricoh-usa.com/en/support-and-downloadmitrex_refsource_MISC
- www.ricoh.com/info/2019/0823_1/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.