CVE-2018-16184

RICOH Interactive Whiteboard D2200 V1.6 to V2.2, D5500 V1.6 to V2.2, D5510 V1.6 to V2.2, and the display versions with RICOH Interactive Whiteboard Controller Type1 V1.6 to V2.2 attached (D5520, D6500, D6510, D7500, D8400) allows remote attackers to execute arbitrary commands via unspecified vectors.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ricoh:d2200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ricoh:d2200:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:ricoh:d5500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ricoh:d5500:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:ricoh:d5510_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ricoh:d5510:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:ricoh:d5520_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ricoh:d5520:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:ricoh:d6500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ricoh:d6500:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:ricoh:d6510_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ricoh:d6510:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:ricoh:d7500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ricoh:d7500:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:ricoh:d8400_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ricoh:d8400:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:52

Type Values Removed Values Added
References () https://jvn.jp/en/jp/JVN55263945/index.html - Third Party Advisory () https://jvn.jp/en/jp/JVN55263945/index.html - Third Party Advisory
References () https://www.ricoh.com/info/2018/1127_1.html - Vendor Advisory () https://www.ricoh.com/info/2018/1127_1.html - Vendor Advisory

Information

Published : 2019-01-09 23:29

Updated : 2024-11-21 03:52


NVD link : CVE-2018-16184

Mitre link : CVE-2018-16184

CVE.ORG link : CVE-2018-16184


JSON object : View

Products Affected

ricoh

  • d6510_firmware
  • d2200
  • d5510
  • d5510_firmware
  • d8400_firmware
  • d6500
  • d5500_firmware
  • d2200_firmware
  • d6500_firmware
  • d6510
  • d8400
  • d7500_firmware
  • d5520
  • d5520_firmware
  • d7500
  • d5500
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')