CNNVD-202506-1767 Information

CNNVD ID

CNNVD-202506-1767

CVE-2025-36506

  • CNNVD Published: 2025-06-13

Description (Chinese)

RICOH Streamline NX V3 PC Client是日本理光(RICOH)公司的一个大规模、集成管理设备的完整解决方案。 RICOH Streamline NX V3 PC Client 3.5.0至3.242.0版本存在安全漏洞,该漏洞源于文件名或路径外部控制,可能导致日志数据覆盖任意文件。

Description (English)

RICOHstreamline NX V3 PC Clinic is a complete solution for a large-scale, integrated management facility at RICOH. There is a security loophole in RICOHstreamline NX V3 PC Clinic versions 3.5.0 to 3.242.0, which stems from the external control of the file name or path and may result in log data covering any file.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

理光

Published

2025-06-13

Last Modified

2026-02-24

References

https://jvn.jp/en/jp/JVN27937557/ https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2025-000004 https://access.redhat.com/security/cve/cve-2025-36506

Patch

https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2025-000004

Share on: