Cross-Site Request Forgery Vulnerability in SEIKO EPSON Printers and Network Interfaces
CVE-2023-27520

6.5MEDIUM

What is CVE-2023-27520?

A Cross-Site Request Forgery (CSRF) vulnerability in SEIKO EPSON printers and network interface Web Config allows remote attackers to hijack user sessions. If a logged-in user accesses a crafted malicious page, the attacker can perform unintended operations on the device without user consent. Web Config, also known as Remote Manager in certain models, is crucial for managing printer settings through a web browser. This vulnerability exposes users to significant risks, highlighting the need for secure network practices.

Affected Version(s)

SEIKO EPSON printers/network interface Web Config = unspecified

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.