Vulnerability Description
Versions of Epson AirPrint released prior to January 19, 2018 contain a reflective cross-site scripting (XSS) vulnerability, which can allow untrusted users on the network to hijack a session cookie or perform other reflected XSS attacks on a currently logged-on user.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Epson | Airprint | < 1-19-2018 |
Related Weaknesses (CWE)
References
- https://blog.rapid7.com/2018/02/08/r7-2017-28-epson-airprint-xss-cve-2018-5550/ExploitThird Party Advisory
- https://epson.com/support/wa00860Vendor Advisory
- https://blog.rapid7.com/2018/02/08/r7-2017-28-epson-airprint-xss-cve-2018-5550/ExploitThird Party Advisory
- https://epson.com/support/wa00860Vendor Advisory
FAQ
What is CVE-2018-5550?
CVE-2018-5550 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Versions of Epson AirPrint released prior to January 19, 2018 contain a reflective cross-site scripting (XSS) vulnerability, which can allow untrusted users on the network to hijack a session cookie o...
How severe is CVE-2018-5550?
CVE-2018-5550 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-5550?
Check the references section above for vendor advisories and patch information. Affected products include: Epson Airprint.