PaperCut Hive Ricoh Embedded Application Administrative Credential Logging Vulnerability
Vulnerability
A vulnerability exists in the PaperCut Hive Ricoh embedded application, where administrative credentials are logged in plain text when the 'Deep Logging' mode is activated. This issue allows an attacker with administrative access to the PaperCut Hive management portal to enable deep logging and later extract sensitive device passwords from the logs, following an authorized user's authentication on the device. The vulnerability could facilitate unauthorized configuration of print hardware or lateral movement within the network.
Impact
Exploitation of this vulnerability could lead to unauthorized access to administrative credentials, allowing for impersonation of other administrators.
Remediation
Users are advised to update the PaperCut Hive Ricoh Embedded App to version 2.2.0 or later.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
