Remote Unauthorized Access to SEIKO EPSON Web Config via Insecure Initial Password Configuration
CVE-2024-47295

8.1HIGH

Key Information:

Vendor
CVE Published:
1 October 2024

What is CVE-2024-47295?

A vulnerability exists in the SEIKO EPSON Web Config that allows a remote unauthenticated attacker to exploit an insecure initial password configuration. This flaw enables the attacker to set an arbitrary password for the device, thereby gaining administrative privileges and compromising the security of the system. Users are advised to refer to the vendor's security advisory for detailed information on affected versions and remediation steps.

Affected Version(s)

Web Config See the information/details provided by the vendor

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.