CVE-2024-36480

CRITICAL

Ricoh Streamline NX PC Client <3.7.2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Use of hard-coded credentials issue exists in Ricoh Streamline NX PC Client ver.3.7.2 and earlier. If this vulnerability is exploited, an attacker may obtain LocalSystem Account of the PC where the product is installed. As a result, unintended operations may be performed on the PC.

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0043
EPSS Percentile 34.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-798
Status published
Products (1)
CVE-2024-36480/Ricoh Streamline NX PC Client ver.3.7.2 and earlier
Published Jun 19, 2024
Tracked Since Feb 18, 2026