First published: Mon Dec 24 2018(Updated: )
An issue was discovered on Epson WorkForce WF-2861 10.48 LQ22I3, 10.51.LQ20I6 and 10.52.LQ17IA devices. They use SNMP to find certain devices on the network, but the default version is v2c, allowing an amplification attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Epson Epson Workforce Wf-2861 Firmware | =10.48_lq22i3 | |
Epson Epson Workforce Wf-2861 Firmware | =10.51.lq20i6 | |
Epson Epson Workforce Wf-2861 Firmware | =10.52.lq17ia | |
Epson Epson Workforce Wf-2861 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18960 is a vulnerability found on Epson WorkForce WF-2861 devices that allows an amplification attack using SNMP.
The severity of CVE-2018-18960 is medium with a CVSS score of 5.9.
CVE-2018-18960 affects Epson WorkForce WF-2861 devices by allowing an amplification attack through SNMP.
To fix CVE-2018-18960, update the firmware of Epson WorkForce WF-2861 devices to version 10.51.LQ20I6 or later.
More information about CVE-2018-18960 can be found at the following link: [https://github.com/epistemophilia/CVEs/blob/master/Epson-WorkForce-WF2861/CVE-2018-18960/poc-cve-2018-18960.py](https://github.com/epistemophilia/CVEs/blob/master/Epson-WorkForce-WF2861/CVE-2018-18960/poc-cve-2018-18960.py)