vendor:
Ricoh Aficio 450/455 printers
by:
Hongzhen Zhou
7.5
CVSS
HIGH
Remote Denial of Service
CWE
Product Name: Ricoh Aficio 450/455 printers
Affected Version From: Ricoh 450/455 printers
Affected Version To: Ricoh 450/455 printers
Patch Exists: NO
Related CWE:
CPE: o:ricoh:aficio_450_printercpe:/o:ricoh:aficio_455_printer
Platforms Tested:
2004
Ricoh 450/455 printers remote denial of service vulnerability
Ricoh 450/455 printers are susceptible to a remote denial of service vulnerability. This issue is due to a failure of the device to properly handle exceptional ICMP packets. Remote attackers may exploit this vulnerability to restart affected devices. Repeated packets may be utilized to sustain the condition, causing the device to repeatedly restart. Source addresses of the malicious ICMP packets may also be spoofed, reducing the likelihood of locating, or blocking access to the attacker. Due to code reuse among devices, it is likely that other printers are also affected. The provided code snippet is an exploit for this vulnerability.
Mitigation:
Apply patches or firmware updates provided by the vendor.