CVE-2018-18006

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
14/12/2018
Last modified:
03/01/2019

Description

Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any externally disclosed myPrint WSDL API, as demonstrated by discovering API secrets of related Google cloud printers, encrypted passwords of mail servers, and names of printed files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ricoh:myprint:2.2.7:*:*:*:*:android:*:*
cpe:2.3:a:ricoh:myprint:2.9.2.4:*:*:*:*:windows:*:*