Записи Epson
34 опубликованных записей вендора epson.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 2,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-306 Missing Authentication for Critical Function3
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-798 Use of Hard-coded Credentials2
- CWE-427 Uncontrolled Search Path Element2
- CWE-276 Incorrect Default Permissions2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
34 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2017-12860Эксплойта нет | The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using aepson · easymp · CWE-798 | Критическая9,8 | — | 3,5 % | 10 окт. 2017 г. |
40В плане | CVE-2017-12861Эксплойта нет | The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using aepson · easymp · CWE-521 | Критическая9,8 | — | 3,3 % | 10 окт. 2017 г. |
39Наблюдать | CVE-2020-28929Эксплойта нет | Unrestricted access to the log downloader functionality in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to remotely repson · eps tse server 8 firmware · CWE-306 | Критическая9,8 | — | 1,2 % | 16 дек. 2020 г. |
39Наблюдать | CVE-2026-23767Эксплойта нет | ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization,epson · sb-h50 firmware · CWE-306 | Критическая9,8 | — | 0,4 % | 5 мар. 2026 г. |
37Наблюдать | CVE-2020-6091Эксплойта нет | An exploitable authentication bypass vulnerability exists in the ESPON Web Control functionality of Epson EB-1470Ui MAIN: 98009273ESWWV107 Mepson · eb-1470ui firmware · CWE-288 | Критическая9,1 | — | 2,3 % | 22 мая 2020 г. |
36Наблюдать | CVE-2018-19248Эксплойта нет | The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Recovery-mode), WF-2861 10.51.LQ20I6, and WF-2861 10.52.LQ17IA devices allows remoteepson · epson workforce wf-2861 firmware · CWE-306 | Критическая9,1 | — | 1,5 % | 24 дек. 2018 г. |
36Наблюдать | CVE-2022-36133Эксплойта нет | The WebConfig functionality of Epson TM-C3500 and TM-C7500 devices with firmware version WAM31500 allows authentication bypass.epson · tm-c3500 firmware · CWE-287 | Критическая9,1 | — | 0,7 % | 25 нояб. 2022 г. |
35Наблюдать | CVE-2018-5550Эксплойта нет | Versions of Epson AirPrint released prior to January 19, 2018 contain a reflective cross-site scripting (XSS) vulnerability, which can allowepson · airprint · CWE-79 | Средняя6,1 | — | 36,9 % | 8 февр. 2018 г. |
35Наблюдать | CVE-2020-12695Proof of concept | The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivenec · wr8165n · CWE-276 | Высокая7,5 | — | 15,2 % | 8 июн. 2020 г. |
35Наблюдать | CVE-2018-0689Эксплойта нет | HTTP header injection vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780Nepson · ds-570w firmware · CWE-113 | Высокая8,8 | — | 1,6 % | 9 янв. 2019 г. |
35Наблюдать | CVE-2020-28931Эксплойта нет | Lack of an anti-CSRF token in the entire administrative interface in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to epson · eps tse server 8 firmware · CWE-352 | Высокая8,8 | — | 0,5 % | 16 дек. 2020 г. |
35Наблюдать | CVE-2019-20458Эксплойта нет | An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices.CWE-276 | Высокая8,8 | — | 0,4 % | 7 нояб. 2024 г. |
35Наблюдать | CVE-2019-20460Эксплойта нет | An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices.CWE-352 | Высокая8,8 | — | 0,2 % | 7 нояб. 2024 г. |
33Наблюдать | CVE-2019-20459Эксплойта нет | An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. | Высокая8,4 | — | 0,3 % | 7 нояб. 2024 г. |
31Наблюдать | CVE-2020-5681Эксплойта нет | Untrusted search path vulnerability in self-extracting files created by EpsonNet SetupManager versions 2.2.14 and earlier, and Offirio Synerepson · epsonnet setupmanager · CWE-427 | Высокая7,8 | — | 0,9 % | 23 дек. 2020 г. |
31Наблюдать | CVE-2020-5674Эксплойта нет | Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan hoepson · album print · CWE-427 | Высокая7,8 | — | 0,3 % | 24 нояб. 2020 г. |
30Наблюдать | CVE-2018-19232Эксплойта нет | The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Recovery-mode), WF-2861 10.51.LQ20I6, and WF-2861 10.52.LQ17IA devices allows remoteepson · epson workforce wf-2861 firmware | Высокая7,5 | — | 1,4 % | 24 дек. 2018 г. |
30Наблюдать | CVE-2018-14902Эксплойта нет | The ContentProvider in the EPSON iPrint application 6.6.3 for Android does not properly restrict data access.epson · iprint · CWE-200 | Высокая7,5 | — | 1,2 % | 30 авг. 2018 г. |
30Наблюдать | CVE-2018-18959Эксплойта нет | An issue was discovered on Epson WorkForce WF-2861 10.48 LQ22I3, 10.51.LQ20I6 and 10.52.LQ17IA devices.epson · epson workforce wf-2861 firmware · CWE-119 | Высокая7,5 | — | 1,2 % | 24 дек. 2018 г. |
30Наблюдать | CVE-2018-14901Эксплойта нет | The EPSON iPrint application 6.6.3 for Android contains hard-coded API and Secret keys for the Dropbox, Box, Evernote and OneDrive services.epson · iprint · CWE-798 | Высокая7,5 | — | 1,1 % | 30 авг. 2018 г. |
30Наблюдать | CVE-2018-14900Эксплойта нет | On EPSON WF-2750 printers with firmware JP02I2, there is no filtering of print jobs.epson · wf-2750 firmware · CWE-417 | Высокая7,5 | — | 1,1 % | 30 авг. 2018 г. |
30Наблюдать | CVE-2023-38556Эксплойта нет | Improper input validation vulnerability in SEIKO EPSON printer Web Config allows a remote attacker to turned off the printer.epson · ep-801a firmware | Высокая7,5 | — | 0,9 % | 2 авг. 2023 г. |
30Наблюдать | CVE-2018-14903Эксплойта нет | EPSON WF-2750 printers with firmware JP02I2 do not properly validate files before running updates, which allows remote attackers to cause a epson · wf-2750 firmware · CWE-346 | Высокая7,5 | — | 0,5 % | 30 авг. 2018 г. |
27Наблюдать | CVE-2015-6034Эксплойта нет | EPSON Network Utility 4.10 uses weak permissions (Everyone: Full Control) for eEBSVC.exe, which allows local users to gain privileges via a epson · network utility · CWE-264 | Средняя6,9 | — | 0,3 % | 28 окт. 2015 г. |
26Наблюдать | CVE-2023-27520Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote unauthenticated attackeepson · lp-9200ps2 firmware · CWE-352 | Средняя6,5 | — | 0,3 % | 11 апр. 2023 г. |
- CVE-2017-1286040В плане
The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using a
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %epson · easymp10 окт. 2017 г.
- CVE-2017-1286140В плане
The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using a
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %epson · easymp10 окт. 2017 г.
- CVE-2020-2892939Наблюдать
Unrestricted access to the log downloader functionality in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to remotely r
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %epson · eps tse server 8 firmware16 дек. 2020 г.
- CVE-2026-2376739Наблюдать
ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization,
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %epson · sb-h50 firmware5 мар. 2026 г.
- CVE-2020-609137Наблюдать
An exploitable authentication bypass vulnerability exists in the ESPON Web Control functionality of Epson EB-1470Ui MAIN: 98009273ESWWV107 M
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %epson · eb-1470ui firmware22 мая 2020 г.
- CVE-2018-1924836Наблюдать
The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Recovery-mode), WF-2861 10.51.LQ20I6, and WF-2861 10.52.LQ17IA devices allows remote
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %epson · epson workforce wf-2861 firmware24 дек. 2018 г.
- CVE-2022-3613336Наблюдать
The WebConfig functionality of Epson TM-C3500 and TM-C7500 devices with firmware version WAM31500 allows authentication bypass.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %epson · tm-c3500 firmware25 нояб. 2022 г.
- CVE-2018-555035Наблюдать
Versions of Epson AirPrint released prior to January 19, 2018 contain a reflective cross-site scripting (XSS) vulnerability, which can allow
СредняяCVSS 6,1Эксплойта нетEPSS 37 %epson · airprint8 февр. 2018 г.
- CVE-2020-1269535Наблюдать
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delive
ВысокаяCVSS 7,5Proof of conceptEPSS 15 %nec · wr8165n8 июн. 2020 г.
- CVE-2018-068935Наблюдать
HTTP header injection vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780N
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %epson · ds-570w firmware9 янв. 2019 г.
- CVE-2020-2893135Наблюдать
Lack of an anti-CSRF token in the entire administrative interface in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %epson · eps tse server 8 firmware16 дек. 2020 г.
- CVE-2019-2045835Наблюдать
An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %7 нояб. 2024 г.
- CVE-2019-2046035Наблюдать
An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %7 нояб. 2024 г.
- CVE-2019-2045933Наблюдать
An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices.
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %7 нояб. 2024 г.
- CVE-2020-568131Наблюдать
Untrusted search path vulnerability in self-extracting files created by EpsonNet SetupManager versions 2.2.14 and earlier, and Offirio Syner
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %epson · epsonnet setupmanager23 дек. 2020 г.
- CVE-2020-567431Наблюдать
Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan ho
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %epson · album print24 нояб. 2020 г.
- CVE-2018-1923230Наблюдать
The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Recovery-mode), WF-2861 10.51.LQ20I6, and WF-2861 10.52.LQ17IA devices allows remote
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %epson · epson workforce wf-2861 firmware24 дек. 2018 г.
- CVE-2018-1490230Наблюдать
The ContentProvider in the EPSON iPrint application 6.6.3 for Android does not properly restrict data access.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %epson · iprint30 авг. 2018 г.
- CVE-2018-1895930Наблюдать
An issue was discovered on Epson WorkForce WF-2861 10.48 LQ22I3, 10.51.LQ20I6 and 10.52.LQ17IA devices.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %epson · epson workforce wf-2861 firmware24 дек. 2018 г.
- CVE-2018-1490130Наблюдать
The EPSON iPrint application 6.6.3 for Android contains hard-coded API and Secret keys for the Dropbox, Box, Evernote and OneDrive services.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %epson · iprint30 авг. 2018 г.
- CVE-2018-1490030Наблюдать
On EPSON WF-2750 printers with firmware JP02I2, there is no filtering of print jobs.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %epson · wf-2750 firmware30 авг. 2018 г.
- CVE-2023-3855630Наблюдать
Improper input validation vulnerability in SEIKO EPSON printer Web Config allows a remote attacker to turned off the printer.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %epson · ep-801a firmware2 авг. 2023 г.
- CVE-2018-1490330Наблюдать
EPSON WF-2750 printers with firmware JP02I2 do not properly validate files before running updates, which allows remote attackers to cause a
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %epson · wf-2750 firmware30 авг. 2018 г.
- CVE-2015-603427Наблюдать
EPSON Network Utility 4.10 uses weak permissions (Everyone: Full Control) for eEBSVC.exe, which allows local users to gain privileges via a
СредняяCVSS 6,9Эксплойта нетEPSS 0 %epson · network utility28 окт. 2015 г.
- CVE-2023-2752026Наблюдать
Cross-site request forgery (CSRF) vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote unauthenticated attacke
СредняяCVSS 6,5Эксплойта нетEPSS 0 %epson · lp-9200ps2 firmware11 апр. 2023 г.