CVE-2012-5002

Ricoh DC Software DL-10 <4.5.0.1 - Buffer Overflow

Title source: llm

Description

Stack-based buffer overflow in SR10 FTP server (SR10.exe) 1.1.0.6 in Ricoh DC Software DL-10 4.5.0.1, when the Log file name option is enabled, allows remote attackers to execute arbitrary code via a long USER FTP command.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/18658
metasploit WORKING POC NORMAL
by Julien Ahrens, sinn3r · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/ftp/ricoh_dl_bof.rb
exploitdb WORKING POC
pythondoswindows
https://www.exploit-db.com/exploits/18643

Scores

EPSS 0.4988
EPSS Percentile 97.8%

Classification

CWE
CWE-119
Status draft

Affected Products (2)

ricoh/dl-10
ricoh/sr10_ftp_server

Timeline

Published Sep 19, 2012
Tracked Since Feb 18, 2026