VYPR
Unrated severityNVD Advisory· Published Aug 26, 2019· Updated Aug 5, 2024

CVE-2019-14308

CVE-2019-14308

Description

Several Ricoh printers have multiple buffer overflows parsing LPD packets, which allow an attacker to cause a denial of service or code execution via crafted requests to the LPD service. Affected firmware versions depend on the printer models. One affected configuration is cpe:2.3:o:ricoh:sp_c250dn_firmware:-:*:*:*:*:*:*:* up to (including) 1.06 running on cpe:2.3:o:ricoh:sp_c250dn:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252dn:-:*:*:*:*:*:*:*. Another affected configuration is cpe:2.3:o:ricoh:sp_c250sf_firmware:-:*:*:*:*:*:*:* up to (including) 1.12 running on cpe:2.3:o:ricoh:sp_c250sf:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252sf:-:*:*:*:*:*:*:*.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A buffer overflow in Ricoh printers' LPD packet parsing allows unauthenticated remote attackers to cause denial of service or execute arbitrary code.

Vulnerability

Several Ricoh printers and Multifunction Printers (MFPs) contain a buffer overflow vulnerability in the parsing of LPD packets (CWE-119), tracked as CVE-2019-14308. The affected firmware versions depend on the printer model; for example, the Ricoh SP C250dn firmware up to version 1.06 and the Ricoh SP C250sf firmware up to version 1.12 are vulnerable [1]. The flaw is triggered when the device processes a specially crafted LPD packet [1].

Exploitation

An attacker can exploit this vulnerability remotely over the network without requiring any authentication [1]. The only prerequisite is that the target printer's LPD service is accessible. By sending a crafted LPD packet, the attacker can trigger a buffer overflow [1].

Impact

Successful exploitation of this buffer overflow can allow a remote attacker to cause a denial-of-service (DoS) condition or to execute arbitrary code on the affected device [1]. The CVSS v3 base score is 9.8, indicating critical severity [1].

Mitigation

Ricoh has released firmware updates to address this vulnerability [1]. Users should apply the appropriate firmware update according to the information provided by the developer [1]. As of the publication date, no workaround has been publicly disclosed [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

5

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.