CVE-2023-23572
https://notcve.org/view.php?id=CVE-2023-23572
Cross-site scripting vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers/network interface via a web browser. According to SEIKO EPSON CORPORATION, it is also called as Remote Manager in some products. Web Config is pre-installed in some printers/network interface provided by SEIKO EPSON CORPORATION. For the details of the affected product names/model numbers, refer to the information provided by the vendor. • https://jvn.jp/en/jp/JVN82424996 https://www.epson.jp/support/misc_t/230308_oshirase.htm • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-27520
https://notcve.org/view.php?id=CVE-2023-27520
Cross-site request forgery (CSRF) vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote unauthenticated attacker to hijack the authentication and perform unintended operations by having a logged-in user view a malicious page. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers/network interface via a web browser. According to SEIKO EPSON CORPORATION, it is also called as Remote Manager in some products. Web Config is pre-installed in some printers/network interface provided by SEIKO EPSON CORPORATION. For the details of the affected product names/model numbers, refer to the information provided by the vendor. • https://jvn.jp/en/jp/JVN82424996 https://www.epson.jp/support/misc_t/230308_oshirase.htm • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2010-3920
https://notcve.org/view.php?id=CVE-2010-3920
The Seiko Epson printer driver installers for LP-S9000 before 4.1.11 and LP-S7100 before 4.1.7, or as downloaded from the vendor between May 2010 and 20101125, set weak permissions for the "C:\Program Files" folder, which might allow local users to bypass intended access restrictions and create or modify arbitrary files and directories. El instalador de drivers de impresora Seiko Epson para LP-S9000 anterior a v4.1.11 y LP-S7100 anterior a v4.1.7, o los descargados del proveedor entre mayo de 2010 y el 25 del noviembre de 2010, modifica los permisos de acceso de la carpeta "C:\Program Files" (C:\Archivos de programa) lo cual puede permitir a los usuarios locales evitar las restricciones de acceso y crear o modificar archivos y direcctorios a su elección. • http://jvn.jp/en/jp/JVN62736872/index.html http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000059.html http://osvdb.org/69678 http://secunia.com/advisories/42540 http://www.epson.jp/support/misc/lps7100_9000/index.htm • CWE-264: Permissions, Privileges, and Access Controls •