CVE-2023-23572: XSS
Cross-site scripting vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers/network interface via a web browser. According to SEIKO EPSON CORPORATION, it is also called as Remote Manager in some products. Web Config is pre-installed in some printers/network interface provided by SEIKO EPSON CORPORATION. For the details of the affected product names/model numbers, refer to the information provided by the vendor.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-23572?
CVE-2023-23572 is categorized as a high-severity cross-site scripting vulnerability.
How do I fix CVE-2023-23572?
To fix CVE-2023-23572, update the affected Epson printer firmware to the latest version provided by Epson.
Who is affected by CVE-2023-23572?
CVE-2023-23572 affects various Epson printers that utilize the SEIKO EPSON network interface Web Config with administrative access.
What kind of attacks can exploit CVE-2023-23572?
An attacker can exploit CVE-2023-23572 to inject arbitrary scripts into the web interface of vulnerable Epson printers.
What is the impact of CVE-2023-23572?
The impact of CVE-2023-23572 includes potential data theft, session hijacking, or redirection of users to malicious websites.