CVE-2019-20460: CSRF
An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. POST requests don't require (anti-)CSRF tokens or other mechanisms for validating that the request is from a legitimate source. In addition, CSRF attacks can be used to send text directly to the RAW printer interface. For example, an attack could deliver a worrisome printout to an end user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-20460?
CVE-2019-20460 is classified as a medium severity vulnerability due to its potential for CSRF attacks.
How do I fix CVE-2019-20460?
To address CVE-2019-20460, ensure that proper CSRF protections, such as tokens, are in place for POST requests.
What devices are affected by CVE-2019-20460?
CVE-2019-20460 affects the Epson Expression Home XP255 model.
What type of attacks can be executed due to CVE-2019-20460?
CVE-2019-20460 can be exploited to conduct CSRF attacks that allow unauthorized commands to be sent to the printer.
Is CVE-2019-20460 related to printer security?
Yes, CVE-2019-20460 is specifically related to security vulnerabilities in the printing functions of the Epson Expression Home XP255.