3 results (0.001 seconds)

CVSS: 7.8EPSS: 0%CPEs: 240EXPL: 0

11 Apr 2023 — Cross-site request forgery (CSRF) vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote unauthenticated attacker to hijack the authentication and perform unintended operations by having a logged-in user view a malicious page. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers/network interface via a web browser. According to SEIKO EPSON CORPORATION, it is also called as Remote Manager in some products. Web Conf... • https://jvn.jp/en/jp/JVN82424996 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 4.8EPSS: 0%CPEs: 100EXPL: 0

11 Apr 2023 — Cross-site scripting vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers/network interface via a web browser. According to SEIKO EPSON CORPORATION, it is also called as Remote Manager in some products. Web Config is pre-installed in some printers/network interface provided ... • https://jvn.jp/en/jp/JVN82424996 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.1EPSS: 0%CPEs: 6EXPL: 0

08 Dec 2010 — The Seiko Epson printer driver installers for LP-S9000 before 4.1.11 and LP-S7100 before 4.1.7, or as downloaded from the vendor between May 2010 and 20101125, set weak permissions for the "C:\Program Files" folder, which might allow local users to bypass intended access restrictions and create or modify arbitrary files and directories. El instalador de drivers de impresora Seiko Epson para LP-S9000 anterior a v4.1.11 y LP-S7100 anterior a v4.1.7, o los descargados del proveedor entre mayo de 2010 y el 25 d... • http://jvn.jp/en/jp/JVN62736872/index.html • CWE-264: Permissions, Privileges, and Access Controls •