Main content

Information

Update: Notice on potential impact of Apache Log4j vulnerability towards Ricoh products and services

December 15, 2021
Last updated: February 17, 2022
First published: December 15, 2021
Ricoh Company, Ltd.

Ricoh understands the importance of security and is committed to managing its products and services with the most advanced security technologies possible for its customers worldwide.

Ricoh is aware of the reported Apache Log4j remote code execution vulnerability CVE-2021-44228. Apache Log4j is an open-source logging JAVA-based library offered by Apache Software Foundation.

Servers operating with Apache Log4j are potentially threatened, allowing a third party to remotely access the server and execute remote code by sending modified data to exploit this vulnerability.
https://logging.apache.org/log4j/2.x/security.html

Upon thorough investigations, Ricoh confirmed the following products and services that it develops, manufactures, and offers are not impacted by this vulnerability, as List 1. For affected products and services, including those affected by related vulnerabilities such as CVE-2021-45046, CVE-2021-45105, CVE-2021-4104, and CVE-2021-44832, Ricoh offers measures detailed below in List 2.

List 1: Ricoh products and services not affected by this vulnerability

Office Products Multifunction Printers/Copiers Black & White MFP
Color MFP
Wide Format MFP
Printers Black & White Laser Printers
Color Laser Printers
Gel Jet Printers
Handy Printers
Printer based MFP
FAX
Digital Duplicators
Projectors
Video Conferencing
Interactive Whiteboards
Remote Communication Gates Remote Communication Gate A2
Remote Communication Gate A
Remote Communication Gate Type N/L/BN1/BM1
Software & Solutions Card Authentication Package Series
Device Manager NX Accounting
Device Manager NX Enterprise
Device Manager NX Lite
Device Manager NX Pro
Docuware
GlobalScan NX
Enhanced Locked Print Series
Printer Driver Packager NX
@Remote Connector NX
Ricoh Smart Integration (RSI) Platform and its applications
RICOH Print Management Cloud
RICOH Streamline NX V2
RICOH Streamline NX V3
Commercial & Industrial Printing Cutsheet Printers
Wide Format Printers
Garment Printers
Software & Apps RICOH InfoPrint® Font Collection
RICOH InfoPrint® PPFA
RICOH InfoPrint® WorkFlow
RICOH Web Enablement Solutions Suite

List 2: Ricoh products and services affected by this vulnerability

The following products have been confirmed to be affected by this vulnerability.

Continuous feed printers RICOH ProVC70000 Fixed release can be provided for these products. Please contact your sales representative.
RICOH ProVC60000
RICOH ProVC40000
Software & Apps RICOH InfoPrint Manager
RICOH ProcessDirector
RICOH Supervisor
RICOH TotalFlow BatchBuilder
RICOH TotalFlow Prep
RICOH TotalFlow Production Manager
Media Management Tool
Media Management Tool-E
Updated program has been released for these products.
Please download the latest firmware from the regional driver download site.

For products and solutions from vendors other than Ricoh, we recommend customers confirm the latest information directly with relevant vendors.

Ricoh is committed to supporting customers across the globe, enabling them to operate Ricoh products equipped with the latest security settings. Please note that this page will be updated if there is a change in the status.


| About Ricoh |

Ricoh is empowering digital workplaces using innovative technologies and services that enable individuals to work smarter from anywhere.

With cultivated knowledge and organizational capabilities nurtured over its 85-years history, Ricoh is a leading provider of digital services and information management, and print and imaging solutions designed to support digital transformation and optimize business performance.

Headquartered in Tokyo, Ricoh Group has major operations throughout the world and its products and services now reach customers in approximately 200 countries and regions. In the financial year ended March 2021, Ricoh Group had worldwide sales of 1,682 billion yen (approx. 15.1 billion USD).

For further information, please visit www.ricoh.com

###

© 2021 RICOH COMPANY, LTD. All rights reserved. All referenced product names are the trademarks of their respective companies.