CVE-2021-33945

high-risk
Published 2022-02-15

RICOH Printer series SP products 320DN, SP 325DNw, SP 320SN, SP 320SFN, SP 325SNw, SP 325SFNw, SP 330SN, Aficio SP 3500SF, SP 221S, SP 220SNw, SP 221SNw, SP 221SF, SP 220SFNw, SP 221SFNw v1.06 were discovered to contain a stack buffer overflow in the file /etc/wpa_supplicant.conf. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

Do I need to act?

-
0.54% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.8/10 Critical
NETWORK / LOW complexity

Affected Products (20)

Sp 320Dn Firmware
Sp 325Dnw Firmware
Sp 320Sn Firmware
Sp 320Sfn Firmware
Sp 325Snw Firmware
Sp 325Sfnw Firmware
Sp 330Sn Firmware
Aficio Sp 3500Sf Firmware
Sp 221S Firmware
Sp 220Snw Firmware
Sp 221Snw Firmware
Sp 221Sf Firmware
Sp 220Sfnw Firmware
Sp 221Sfnw Firmware
M C2000 Firmware
M C250Fwb Firmware
M C250Fw Firmware
Sp C260Sfnw Firmware
Sp C262Sfnw Firmware
Sp C261Sfnw Firmware

Affected Vendors

62
/ 100
high-risk
Severity 32/34 · Critical
Exploitability 2/34 · Minimal
Exposure 28/34 · Critical