CVE-2012-5002

Ricoh DC Software DL-10 <4.5.0.1 - Buffer Overflow

Title source: llm

Description

Stack-based buffer overflow in SR10 FTP server (SR10.exe) 1.1.0.6 in Ricoh DC Software DL-10 4.5.0.1, when the Log file name option is enabled, allows remote attackers to execute arbitrary code via a long USER FTP command.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/18658
exploitdb WORKING POC
pythondoswindows
https://www.exploit-db.com/exploits/18643
metasploit WORKING POC NORMAL
by Julien Ahrens, sinn3r · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/ftp/ricoh_dl_bof.rb

Scores

EPSS 0.4988
EPSS Percentile 97.8%

Details

CWE
CWE-119
Status published
Products (2)
ricoh/dl-10 4.5.0.1
ricoh/sr10_ftp_server 1.1.0.6
Published Sep 19, 2012
Tracked Since Feb 18, 2026