MEDIUM · 4.8

CVE-2023-23572

Cross-site scripting vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. [Note] We...

Vulnerability Description

Cross-site scripting vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers/network interface via a web browser. According to SEIKO EPSON CORPORATION, it is also called as Remote Manager in some products. Web Config is pre-installed in some printers/network interface provided by SEIKO EPSON CORPORATION. For the details of the affected product names/model numbers, refer to the information provided by the vendor.

CVSS Score

4.8

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
EpsonLp-9200Ps2 Firmware-
EpsonLp-9200Ps2-
EpsonLp-9200Ps3 Firmware-
EpsonLp-9200Ps3-
EpsonLp-8200C Firmware-
EpsonLp-8200C-
EpsonLp-9600 Firmware-
EpsonLp-9600-
EpsonLp-9600S Firmware-
EpsonLp-9600S-
EpsonLp-9300 Firmware-
EpsonLp-9300-
EpsonLp-8500C Firmware-
EpsonLp-8500C-
EpsonLp-8700Ps3 Firmware-
EpsonLp-8700Ps3-
EpsonLp-9800C Firmware-
EpsonLp-9800C-
EpsonLp-S5500 Firmware-
EpsonLp-S5500-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-23572?

CVE-2023-23572 is a vulnerability with a CVSS score of 4.8 (MEDIUM). Cross-site scripting vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. [Note] We...

How severe is CVE-2023-23572?

CVE-2023-23572 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-23572?

Check the references section above for vendor advisories and patch information. Affected products include: Epson Lp-9200Ps2 Firmware, Epson Lp-9200Ps2, Epson Lp-9200Ps3 Firmware, Epson Lp-9200Ps3, Epson Lp-8200C Firmware.