Cross-site request forgery (CSRF) vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote unauthenticated attacker to hijack the authentication and perform unintended operations by having a logged-in user view a malicious page. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers/network interface via a web browser. According to SEIKO EPSON CORPORATION, it is also called as Remote Manager in some products. Web Config is pre-installed in some printers/network interface provided by SEIKO EPSON CORPORATION. For the details of the affected product names/model numbers, refer to the information provided by the vendor.
References
Link Resource
https://jvn.jp/en/jp/JVN82424996/ Third Party Advisory
https://www.epson.jp/support/misc_t/230308_oshirase.htm Mitigation Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: jpcert

Published: 2023-04-11T00:00:00

Updated: 2023-04-11T00:00:00

Reserved: 2023-03-02T00:00:00


Link: CVE-2023-27520

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-04-11T09:15:08.157

Modified: 2023-08-24T13:33:15.207


Link: CVE-2023-27520

JSON object: View

cve-icon Redhat Information

No data.

CWE