4.8

CVE-2023-23572

Cross-site scripting vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers/network interface via a web browser. According to SEIKO EPSON CORPORATION, it is also called as Remote Manager in some products. Web Config is pre-installed in some printers/network interface provided by SEIKO EPSON CORPORATION. For the details of the affected product names/model numbers, refer to the information provided by the vendor.

Data is provided by the National Vulnerability Database (NVD)
EpsonLp-9200ps2 Firmware Version-
   EpsonLp-9200ps2 Version-
EpsonLp-9200ps3 Firmware Version-
   EpsonLp-9200ps3 Version-
EpsonLp-8200c Firmware Version-
   EpsonLp-8200c Version-
EpsonLp-9600 Firmware Version-
   EpsonLp-9600 Version-
EpsonLp-9600s Firmware Version-
   EpsonLp-9600s Version-
EpsonLp-9300 Firmware Version-
   EpsonLp-9300 Version-
EpsonLp-8500c Firmware Version-
   EpsonLp-8500c Version-
EpsonLp-8700ps3 Firmware Version-
   EpsonLp-8700ps3 Version-
EpsonLp-9800c Firmware Version-
   EpsonLp-9800c Version-
EpsonLp-s5500 Firmware Version-
   EpsonLp-s5500 Version-
EpsonLp-9200b Firmware Version-
   EpsonLp-9200b Version-
EpsonLp-9200c Firmware Version-
   EpsonLp-9200c Version-
EpsonLp-s4500 Firmware Version-
   EpsonLp-s4500 Version-
EpsonLp-s6500 Firmware Version-
   EpsonLp-s6500 Version-
EpsonLp-s7000 Firmware Version-
   EpsonLp-s7000 Version-
EpsonLp-s5000 Firmware Version-
   EpsonLp-s5000 Version-
EpsonLp-s4000 Firmware Version-
   EpsonLp-s4000 Version-
EpsonLp-s6000 Firmware Version-
   EpsonLp-s6000 Version-
EpsonLp-s5300 Firmware Version-
   EpsonLp-s5300 Version-
EpsonLp-s5300r Firmware Version-
   EpsonLp-s5300r Version-
EpsonLp-s300n Firmware Version-
   EpsonLp-s300n Version-
EpsonLp-s310n Firmware Version-
   EpsonLp-s310n Version-
EpsonLp-s3000 Firmware Version-
   EpsonLp-s3000 Version-
EpsonLp-s3000r Firmware Version-
   EpsonLp-s3000r Version-
EpsonLp-s3000z Firmware Version-
   EpsonLp-s3000z Version-
EpsonLp-s3000ps Firmware Version-
   EpsonLp-s3000ps Version-
EpsonLp-s7500 Firmware Version-
   EpsonLp-s7500 Version-
EpsonLp-s7500ps Firmware Version-
   EpsonLp-s7500ps Version-
EpsonLp-s3500 Firmware Version-
   EpsonLp-s3500 Version-
EpsonLp-s4200 Firmware Version-
   EpsonLp-s4200 Version-
EpsonLp-s9000 Firmware Version-
   EpsonLp-s9000 Version-
EpsonLp-s7100 Firmware Version-
   EpsonLp-s7100 Version-
EpsonLp-s8100 Firmware Version-
   EpsonLp-s8100 Version-
EpsonPrifnw1 Firmware Version-
   EpsonPrifnw1 Version-
EpsonPrifnw1s Firmware Version-
   EpsonPrifnw1s Version-
EpsonPrifnw2 Firmware Version-
   EpsonPrifnw2 Version-
EpsonPrifnw2ac Firmware Version-
   EpsonPrifnw2ac Version-
EpsonPrifnw2s Firmware Version-
   EpsonPrifnw2s Version-
EpsonPrifnw2sac Firmware Version-
   EpsonPrifnw2sac Version-
EpsonPrifnw3 Firmware Version-
   EpsonPrifnw3 Version-
EpsonPrifnw3s Firmware Version-
   EpsonPrifnw3s Version-
EpsonPrifnw6 Firmware Version-
   EpsonPrifnw6 Version-
EpsonPrifnw7 Firmware Version-
   EpsonPrifnw7 Version-
EpsonPrifnw7u Firmware Version-
   EpsonPrifnw7u Version-
EpsonPrifnw7s Firmware Version-
   EpsonPrifnw7s Version-
EpsonPa-w11g Firmware Version-
   EpsonPa-w11g Version-
EpsonPa-w11g2 Firmware Version-
   EpsonPa-w11g2 Version-
EpsonEsnsb1 Firmware Version-
   EpsonEsnsb1 Version-
EpsonEsnsb2 Firmware Version-
   EpsonEsnsb2 Version-
EpsonEsifnw1 Firmware Version-
   EpsonEsifnw1 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.28% 0.485
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.8 1.7 2.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 4.8 1.7 2.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.