Results 1 to 5 of 5
  1. #1
    Senior Tech 100+ Posts MitchD's Avatar
    Join Date
    Oct 2012
    Location
    Springfield, IL
    Posts
    164
    Rep Power
    26

    Disabling TLS 1.0 and SSL 3.0 on a MP C4502

    I received this from a customer of mine................


    "I知 still battling some serious vulnerabilities on the Ricoh C4502. I知 attaching my documentation, but TLS 1.0 and SSL 3.0, among other items are still being flagged as on by Rapid7 scanner. What do you suggest?"



    ricoh 4502 security settings.jpgricoh 4502 SSL TLS screen.jpgricoh 4502 Nexpose Security Console __ Asset Summary.pdfcopier tls vuln.jpgcopier ssl vuln.jpg

    Any ideas? Looks like he has everything unchecked correctly.

    Thanks
    "Heavy music to the normal ear is nothing but a loud annoyance. Most people think of it as obnoxious, talentless music but to someone who really listens and is really in love with music knows how beautiful and amazing it can be" Tommy Rogers of Between The Buried and Me"

  2. #2
    Retired 10,000+ Posts
    Disabling TLS 1.0 and SSL 3.0 on a MP C4502

    slimslob's Avatar
    Join Date
    May 2013
    Location
    Bakersfield, CA
    Posts
    34,224
    Rep Power
    991

    Re: Disabling TLS 1.0 and SSL 3.0 on a MP C4502

    I am seeing one major discrepancy on the Nexpose Security Console report. It is referring to the name as lanierld525c.mjmec.local. A Lanier LD525 would be an Aficio MP C2550. This tells me that a lazy tech or IT changed the network name to match that of a previous machine. This in and of itself can introduce potential vulnerabilities, both actual and falsely reported. SMB signing was a problem preventing scan to anything after Windows 98 on older model Ricohs that are not up to date on their firmware. Also some of the vulnerabilities have to do with sending to the C4502.

  3. #3
    Just a tech 250+ Posts keithxxiii's Avatar
    Join Date
    Nov 2014
    Posts
    465
    Rep Power
    28

    Re: Disabling TLS 1.0 and SSL 3.0 on a MP C4502

    Some device settings can be disabled by using telnet
    Aye! Cut the crap

  4. #4
    Senior Tech 100+ Posts MitchD's Avatar
    Join Date
    Oct 2012
    Location
    Springfield, IL
    Posts
    164
    Rep Power
    26

    Re: Disabling TLS 1.0 and SSL 3.0 on a MP C4502

    Quote Originally Posted by slimslob View Post
    I am seeing one major discrepancy on the Nexpose Security Console report. It is referring to the name as lanierld525c.mjmec.local. A Lanier LD525 would be an Aficio MP C2550. This tells me that a lazy tech or IT changed the network name to match that of a previous machine. This in and of itself can introduce potential vulnerabilities, both actual and falsely reported. SMB signing was a problem preventing scan to anything after Windows 98 on older model Ricohs that are not up to date on their firmware. Also some of the vulnerabilities have to do with sending to the C4502.
    HA! I just noticed that. I'm going on site this morning to pull down a full SMC report at the request of Ricoh Tech Support. I will double check that host name. Tech support said they are aware of an issue of the ports not being closed even tho the protocol is turned off. Engineering is working on it.

    We will see.........
    "Heavy music to the normal ear is nothing but a loud annoyance. Most people think of it as obnoxious, talentless music but to someone who really listens and is really in love with music knows how beautiful and amazing it can be" Tommy Rogers of Between The Buried and Me"

  5. #5
    Senior Tech 100+ Posts MitchD's Avatar
    Join Date
    Oct 2012
    Location
    Springfield, IL
    Posts
    164
    Rep Power
    26

    Re: Disabling TLS 1.0 and SSL 3.0 on a MP C4502

    Quote Originally Posted by keithxxiii View Post
    Some device settings can be disabled by using telnet
    I thought this too, I went through telnet and didn't see anything. Ricoh Tech Support is on the case. I will let you know what they say.
    "Heavy music to the normal ear is nothing but a loud annoyance. Most people think of it as obnoxious, talentless music but to someone who really listens and is really in love with music knows how beautiful and amazing it can be" Tommy Rogers of Between The Buried and Me"

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Get the Android App
click or scan for the Copytechnet Mobile App

-= -= -= -= -=


IDrive Remote Backup

Lunarpages Internet Solutions

Advertise on Copytechnet

Your Link Here