VulnerabilityModified
CVE-2022-36133
The WebConfig functionality of Epson TM-C3500 and TM-C7500 devices with firmware version WAM31500 allows authentication bypass.
CRITICAL 9.1EPSS 0.71%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.71%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The WebConfig functionality of Epson TM-C3500 and TM-C7500 devices with firmware version WAM31500 allows authentication bypass.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- EPSS
- 0.71% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- epson/tm-c3500 firmware · epson/tm-c3510 firmware · epson/tm-c3520 firmware · epson/tm-c7500 firmware · epson/tm-c7500g firmware · epson/tm-c7510 firmware · epson/tm-c7510g firmware · epson/tm-c7520 firmware · epson/tm-c7520g firmware
- Source
- cve@mitre.org
References
- https://download.epson-biz.com/epson/epson_public_document.php?name=Infomation_history.pdfVendor Advisory
- https://download.epson-biz.com/modules/colorworks/Product, Vendor Advisory
- https://download.epson-biz.com/epson/epson_public_document.php?name=Infomation_history.pdfVendor Advisory
- https://download.epson-biz.com/modules/colorworks/Product, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.