MEDIUM · 6.5

CVE-2023-27520

Cross-site request forgery (CSRF) vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote unauthenticated attacker to hijack the authentication and perform unintended operat...

Vulnerability Description

Cross-site request forgery (CSRF) vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote unauthenticated attacker to hijack the authentication and perform unintended operations by having a logged-in user view a malicious page. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers/network interface via a web browser. According to SEIKO EPSON CORPORATION, it is also called as Remote Manager in some products. Web Config is pre-installed in some printers/network interface provided by SEIKO EPSON CORPORATION. For the details of the affected product names/model numbers, refer to the information provided by the vendor.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
EpsonLp-9200Ps2 Firmware-
EpsonLp-9200Ps2-
EpsonLp-9200Ps3 Firmware-
EpsonLp-9200Ps3-
EpsonLp-8200C Firmware-
EpsonLp-8200C-
EpsonLp-9600 Firmware-
EpsonLp-9600-
EpsonLp-9600S Firmware-
EpsonLp-9600S-
EpsonLp-9300 Firmware-
EpsonLp-9300-
EpsonLp-8500C Firmware-
EpsonLp-8500C-
EpsonLp-8700Ps3 Firmware-
EpsonLp-8700Ps3-
EpsonLp-9800C Firmware-
EpsonLp-9800C-
EpsonLp-S5500 Firmware-
EpsonLp-S5500-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-27520?

CVE-2023-27520 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Cross-site request forgery (CSRF) vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote unauthenticated attacker to hijack the authentication and perform unintended operat...

How severe is CVE-2023-27520?

CVE-2023-27520 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-27520?

Check the references section above for vendor advisories and patch information. Affected products include: Epson Lp-9200Ps2 Firmware, Epson Lp-9200Ps2, Epson Lp-9200Ps3 Firmware, Epson Lp-9200Ps3, Epson Lp-8200C Firmware.