External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an attacker sends a specially crafted request, arbitrary files in the file system can be overwritten with log data.
History

Fri, 13 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 13 Jun 2025 08:30:00 +0000

Type Values Removed Values Added
Description External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an attacker sends a specially crafted request, arbitrary files in the file system can be overwritten with log data.
Weaknesses CWE-73
References
Metrics cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2025-06-13T08:18:49.469Z

Updated: 2025-06-13T15:13:20.611Z

Reserved: 2025-06-12T01:53:40.407Z

Link: CVE-2025-36506

cve-icon Vulnrichment

Updated: 2025-06-13T15:13:15.171Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-13T09:15:19.223

Modified: 2025-06-16T12:32:18.840

Link: CVE-2025-36506

cve-icon Redhat

No data.