Cross-site scripting vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers/network interface via a web browser. According to SEIKO EPSON CORPORATION, it is also called as Remote Manager in some products. Web Config is pre-installed in some printers/network interface provided by SEIKO EPSON CORPORATION. For the details of the affected product names/model numbers, refer to the information provided by the vendor.

Project Subscriptions

Vendors Products
Esifnw1 Subscribe
Esifnw1 Firmware Subscribe
Esnsb1 Firmware Subscribe
Esnsb2 Firmware Subscribe
Lp-8200c Subscribe
Lp-8200c Firmware Subscribe
Lp-8500c Subscribe
Lp-8500c Firmware Subscribe
Lp-8700ps3 Subscribe
Lp-8700ps3 Firmware Subscribe
Lp-9200b Subscribe
Lp-9200b Firmware Subscribe
Lp-9200c Subscribe
Lp-9200c Firmware Subscribe
Lp-9200ps2 Subscribe
Lp-9200ps2 Firmware Subscribe
Lp-9200ps3 Subscribe
Lp-9200ps3 Firmware Subscribe
Lp-9300 Subscribe
Lp-9300 Firmware Subscribe
Lp-9600 Subscribe
Lp-9600 Firmware Subscribe
Lp-9600s Subscribe
Lp-9600s Firmware Subscribe
Lp-9800c Subscribe
Lp-9800c Firmware Subscribe
Lp-s3000 Subscribe
Lp-s3000 Firmware Subscribe
Lp-s3000ps Subscribe
Lp-s3000ps Firmware Subscribe
Lp-s3000r Subscribe
Lp-s3000r Firmware Subscribe
Lp-s3000z Subscribe
Lp-s3000z Firmware Subscribe
Lp-s300n Subscribe
Lp-s300n Firmware Subscribe
Lp-s310n Subscribe
Lp-s310n Firmware Subscribe
Lp-s3500 Subscribe
Lp-s3500 Firmware Subscribe
Lp-s4000 Subscribe
Lp-s4000 Firmware Subscribe
Lp-s4200 Subscribe
Lp-s4200 Firmware Subscribe
Lp-s4500 Subscribe
Lp-s4500 Firmware Subscribe
Lp-s5000 Subscribe
Lp-s5000 Firmware Subscribe
Lp-s5300 Subscribe
Lp-s5300 Firmware Subscribe
Lp-s5300r Subscribe
Lp-s5300r Firmware Subscribe
Lp-s5500 Subscribe
Lp-s5500 Firmware Subscribe
Lp-s6000 Subscribe
Lp-s6000 Firmware Subscribe
Lp-s6500 Subscribe
Lp-s6500 Firmware Subscribe
Lp-s7000 Subscribe
Lp-s7000 Firmware Subscribe
Lp-s7100 Subscribe
Lp-s7100 Firmware Subscribe
Lp-s7500 Subscribe
Lp-s7500 Firmware Subscribe
Lp-s7500ps Subscribe
Lp-s7500ps Firmware Subscribe
Lp-s8100 Subscribe
Lp-s8100 Firmware Subscribe
Lp-s9000 Subscribe
Lp-s9000 Firmware Subscribe
Pa-w11g Subscribe
Pa-w11g2 Subscribe
Pa-w11g2 Firmware Subscribe
Pa-w11g Firmware Subscribe
Prifnw1 Subscribe
Prifnw1 Firmware Subscribe
Prifnw1s Subscribe
Prifnw1s Firmware Subscribe
Prifnw2 Subscribe
Prifnw2 Firmware Subscribe
Prifnw2ac Subscribe
Prifnw2ac Firmware Subscribe
Prifnw2s Subscribe
Prifnw2s Firmware Subscribe
Prifnw2sac Subscribe
Prifnw2sac Firmware Subscribe
Prifnw3 Subscribe
Prifnw3 Firmware Subscribe
Prifnw3s Subscribe
Prifnw3s Firmware Subscribe
Prifnw6 Subscribe
Prifnw6 Firmware Subscribe
Prifnw7 Subscribe
Prifnw7 Firmware Subscribe
Prifnw7s Subscribe
Prifnw7s Firmware Subscribe
Prifnw7u Subscribe
Prifnw7u Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-27672 Cross-site scripting vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers/network interface via a web browser. According to SEIKO EPSON CORPORATION, it is also called as Remote Manager in some products. Web Config is pre-installed in some printers/network interface provided by SEIKO EPSON CORPORATION. For the details of the affected product names/model numbers, refer to the information provided by the vendor.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 11 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2025-02-11T15:51:26.574Z

Reserved: 2023-03-02T00:00:00.000Z

Link: CVE-2023-23572

cve-icon Vulnrichment

Updated: 2024-08-02T10:35:33.453Z

cve-icon NVD

Status : Modified

Published: 2023-04-11T09:15:07.707

Modified: 2025-02-11T16:15:31.730

Link: CVE-2023-23572

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses