Ricoh understands the importance of security and is committed to managing its products and services with the most advanced security technologies possible for its customers worldwide.
Ricoh is aware of the reported "Cross-site scripting vulnerable" (CVE-2022-37406) affects MP C401SP/C401SRSP(The model with Smart Operation Panel).
Ricoh offers measures detailed below.
Arbitrary scripts may be executed on the web browser of a user who is logged in with administrative privileges.
Products or Services | Components | Versions |
---|---|---|
MP C401SP/C401SRSP(The model with Smart Operation Panel) | Firmware | Web Support 2.04 or earlier |
How to view the firmware version:
1. Access Web Image Monitor from your browser.
https://""IP address or hostname of the device""
2. Log in with Administrator privileges.
3. Navigate to Device Management > Configuration > Device Settings > Firmware Update
Please download the updated firmware at the following links:
https://support.ricoh.com/bb/html/dr_ut_e/rc3/model/mpc401/mpc401.htm
Please contact your local Ricoh representative or dealer if you have any queries.
The distribution URL of this page:
https://www.ricoh.com/products/security/vulnerabilities/adv?id=ricoh-prod000256-2023-000006 Please note that any copy or paraphrase of the text of this document that differs in content from the distribution URL link, or omits the URL, is an uncontrolled copy and may lack important information or contain factual errors.