CVE-2023-38556
https://notcve.org/view.php?id=CVE-2023-38556
Improper input validation vulnerability in SEIKO EPSON printer Web Config allows a remote attacker to turned off the printer. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers via a web browser. Web Config is pre-installed in some printers provided by SEIKO EPSON CORPORATION. For the details of the affected product names/model numbers, refer to the information provided by the vendor. • https://jvn.jp/en/jp/JVN61337171 https://www.epson.jp/support/misc_t/230802_oshirase.htm •
CVE-2023-23572
https://notcve.org/view.php?id=CVE-2023-23572
Cross-site scripting vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers/network interface via a web browser. According to SEIKO EPSON CORPORATION, it is also called as Remote Manager in some products. Web Config is pre-installed in some printers/network interface provided by SEIKO EPSON CORPORATION. For the details of the affected product names/model numbers, refer to the information provided by the vendor. • https://jvn.jp/en/jp/JVN82424996 https://www.epson.jp/support/misc_t/230308_oshirase.htm • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-27520
https://notcve.org/view.php?id=CVE-2023-27520
Cross-site request forgery (CSRF) vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote unauthenticated attacker to hijack the authentication and perform unintended operations by having a logged-in user view a malicious page. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers/network interface via a web browser. According to SEIKO EPSON CORPORATION, it is also called as Remote Manager in some products. Web Config is pre-installed in some printers/network interface provided by SEIKO EPSON CORPORATION. For the details of the affected product names/model numbers, refer to the information provided by the vendor. • https://jvn.jp/en/jp/JVN82424996 https://www.epson.jp/support/misc_t/230308_oshirase.htm • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2022-36133
https://notcve.org/view.php?id=CVE-2022-36133
The WebConfig functionality of Epson TM-C3500 and TM-C7500 devices with firmware version WAM31500 allows authentication bypass. La funcionalidad WebConfig de los dispositivos Epson TM-C3500 y TM-C7500 con versión de firmware WAM31500 permite omitir la autenticación. • https://download.epson-biz.com/epson/epson_public_document.php?name=Infomation_history.pdf https://download.epson-biz.com/modules/colorworks •
CVE-2020-9453
https://notcve.org/view.php?id=CVE-2020-9453
In Epson iProjection v2.30, the driver file EMP_MPAU.sys allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C402406 and IOCtl 0x9C40240A. (0x9C402402 has only a NULL pointer dereference.) This affects \Device\EMPMPAUIO and \DosDevices\EMPMPAU. En Epson iProjection versión v2.30, el archivo del controlador EMP_MPAU.sys permite a usuarios locales causar una denegación de servicio (BSOD) o posiblemente tener otro impacto no especificado debido a que no se comprueban los valores de entrada de IOCtl 0x9C402406 e IOCtl 0x9C40240A. (0x9C402402 sólo presenta una desreferencia de puntero NULL.) Esto afecta a \Device\EMPMPAUIO y \DosDevices\EMPMPAU • https://epson.com https://epson.com/Support/wa00936 https://github.com/FULLSHADE/Kernel-exploits https://github.com/FULLSHADE/Kernel-exploits/tree/master/EMP_MPAU.sys • CWE-476: NULL Pointer Dereference •