CVE-2023-38556
Improper input validation vulnerability in SEIKO EPSON printer Web Config allows a remote attacker to turned off the printer. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers via a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.85%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Improper input validation vulnerability in SEIKO EPSON printer Web Config allows a remote attacker to turned off the printer. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers via a web browser. Web Config is pre-installed in some printers provided by SEIKO EPSON CORPORATION. For the details of the affected product names/model numbers, refer to the information provided by the vendor.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.85% probability · 56th percentile
- CISA KEV
- Not listed
- Affected
- epson/ep-801a firmware · epson/ep-802a firmware · epson/ep-901a firmware · epson/ep-901f firmware · epson/ep-902a firmware · epson/pa-tcu1 firmware · epson/pm-t960 firmware · epson/pm-t990 firmware · epson/px-201 firmware · epson/px-502a firmware · epson/px-601f firmware · epson/px-602f firmware
- Source
- vultures@jpcert.or.jp
References
- https://jvn.jp/en/jp/JVN61337171/Third Party Advisory
- https://www.epson.jp/support/misc_t/230802_oshirase.htmVendor Advisory
- https://jvn.jp/en/jp/JVN61337171/Third Party Advisory
- https://www.epson.jp/support/misc_t/230802_oshirase.htmVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.