A Server-Side Request Forgery vulnerability

21 Feb 2023

First published: 04:00 pm on February 21, 2023 (2023-02-21T14:00:00+09:00)

Ricoh Company, Ltd.

Ricoh understands the importance of security and is committed to managing its products and services with the most advanced security technologies possible for its customers worldwide.

Ricoh has identified a Server-Side Request Forgery (SSRF) vulnerability(CVE-2023-23560) in some of our devices listed below.

SSRF can occur because of a lack of input validation.

Successful exploitation of this vulnerability can lead to an attacker being able to remotely execute arbitrary code on a device. Please refer to the following URL for further details:
https://nvd.nist.gov/vuln/detail/CVE-2023-23560

 Vulnerability Information IDricoh-2023-000002
 Version1.00E
 CVE ID(CWE ID)CVE-2023-23560 (CWE-918)
 CVSSv3 score9.0  High 

List 1: Ricoh products affected by this vulnerability

Product/service  Link to details
M C240FWAffected. For details, please refer to the following URL.
https://www.ricoh.com/products/security/vulnerabilities/adv?id=ricoh-prod000067-2023-000002
P C200WAffected. For details, please refer to the following URL.
https://www.ricoh.com/products/security/vulnerabilities/adv?id=ricoh-prod000065-2023-000002

Contact

Please contact your local Ricoh representative or dealer if you have any queries. 

History:

2023-02-21T14:00:00+09:00 : 1.00E Initial public release