Impact
Printers and multifunction printers from Ricoh do not limit the destinations that can be reached through SSH port forwarding. An attacker who can connect to the device’s SSH service can create tunnels to arbitrary internal hosts, effectively bypassing network segmentation and gaining access to resources that should be isolated. The effect is the extension of attacker privileges across the local network and the exposure of internal services.
Affected Systems
Ricoh Company printers and multifunction printers (MFPs). No specific model or firmware version information was provided, so all Ricoh devices that support SSH are potentially affected.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the EPSS score of less than 1% suggests a currently low exploitation probability. The vulnerability is not yet catalogued as a known exploited weakness in CISA KEV. Exploitation requires that SSH be enabled and that the attacker can authenticate to the device. Once authenticated, the lack of port‑forwarding restrictions allows the attacker to connect to any internal node reachable from the device’s network interface.
OpenCVE Enrichment