CVE-2023-23572

Cross-site scripting vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers/network interface via a web browser. According to SEIKO EPSON CORPORATION, it is also called as Remote Manager in some products. Web Config is pre-installed in some printers/network interface provided by SEIKO EPSON CORPORATION. For the details of the affected product names/model numbers, refer to the information provided by the vendor.
References
Link Resource
https://jvn.jp/en/jp/JVN82424996/ Third Party Advisory
https://www.epson.jp/support/misc_t/230308_oshirase.htm Mitigation Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:epson:lp-9200ps2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-9200ps2:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:epson:lp-9200ps3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-9200ps3:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:epson:lp-8200c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-8200c:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:epson:lp-9600_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-9600:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:epson:lp-9600s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-9600s:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:epson:lp-9300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-9300:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:epson:lp-8500c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-8500c:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:epson:lp-8700ps3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-8700ps3:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:epson:lp-9800c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-9800c:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:epson:lp-s5500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s5500:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:epson:lp-9200b_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-9200b:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:epson:lp-9200c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-9200c:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:epson:lp-s4500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s4500:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:epson:lp-s6500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s6500:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:epson:lp-s7000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s7000:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:epson:lp-s5000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s5000:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:epson:lp-s4000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s4000:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:epson:lp-s6000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s6000:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:epson:lp-s5300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s5300:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:epson:lp-s5300r_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s5300r:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:epson:lp-s300n_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s300n:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:epson:lp-s310n_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s310n:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:epson:lp-s3000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s3000:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:epson:lp-s3000r_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s3000r:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:epson:lp-s3000z_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s3000z:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:epson:lp-s3000ps_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s3000ps:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:epson:lp-s7500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s7500:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:epson:lp-s7500ps_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s7500ps:-:*:*:*:*:*:*:*

Configuration 29 (hide)

AND
cpe:2.3:o:epson:lp-s3500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s3500:-:*:*:*:*:*:*:*

Configuration 30 (hide)

AND
cpe:2.3:o:epson:lp-s4200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s4200:-:*:*:*:*:*:*:*

Configuration 31 (hide)

AND
cpe:2.3:o:epson:lp-s9000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s9000:-:*:*:*:*:*:*:*

Configuration 32 (hide)

AND
cpe:2.3:o:epson:lp-s7100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s7100:-:*:*:*:*:*:*:*

Configuration 33 (hide)

AND
cpe:2.3:o:epson:lp-s8100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s8100:-:*:*:*:*:*:*:*

Configuration 34 (hide)

AND
cpe:2.3:o:epson:prifnw1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:prifnw1:-:*:*:*:*:*:*:*

Configuration 35 (hide)

AND
cpe:2.3:o:epson:prifnw1s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:prifnw1s:-:*:*:*:*:*:*:*

Configuration 36 (hide)

AND
cpe:2.3:o:epson:prifnw2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:prifnw2:-:*:*:*:*:*:*:*

Configuration 37 (hide)

AND
cpe:2.3:o:epson:prifnw2ac_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:prifnw2ac:-:*:*:*:*:*:*:*

Configuration 38 (hide)

AND
cpe:2.3:o:epson:prifnw2s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:prifnw2s:-:*:*:*:*:*:*:*

Configuration 39 (hide)

AND
cpe:2.3:o:epson:prifnw2sac_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:prifnw2sac:-:*:*:*:*:*:*:*

Configuration 40 (hide)

AND
cpe:2.3:o:epson:prifnw3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:prifnw3:-:*:*:*:*:*:*:*

Configuration 41 (hide)

AND
cpe:2.3:o:epson:prifnw3s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:prifnw3s:-:*:*:*:*:*:*:*

Configuration 42 (hide)

AND
cpe:2.3:o:epson:prifnw6_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:prifnw6:-:*:*:*:*:*:*:*

Configuration 43 (hide)

AND
cpe:2.3:o:epson:prifnw7_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:prifnw7:-:*:*:*:*:*:*:*

Configuration 44 (hide)

AND
cpe:2.3:o:epson:prifnw7u_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:prifnw7u:-:*:*:*:*:*:*:*

Configuration 45 (hide)

AND
cpe:2.3:o:epson:prifnw7s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:prifnw7s:-:*:*:*:*:*:*:*

Configuration 46 (hide)

AND
cpe:2.3:o:epson:pa-w11g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:pa-w11g:-:*:*:*:*:*:*:*

Configuration 47 (hide)

AND
cpe:2.3:o:epson:pa-w11g2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:pa-w11g2:-:*:*:*:*:*:*:*

Configuration 48 (hide)

AND
cpe:2.3:o:epson:esnsb1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:esnsb1:-:*:*:*:*:*:*:*

Configuration 49 (hide)

AND
cpe:2.3:o:epson:esnsb2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:esnsb2:-:*:*:*:*:*:*:*

Configuration 50 (hide)

AND
cpe:2.3:o:epson:esifnw1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:esifnw1:-:*:*:*:*:*:*:*

History

18 Apr 2023, 13:41

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-11 09:15

Updated : 2024-02-04 23:37


NVD link : CVE-2023-23572

Mitre link : CVE-2023-23572

CVE.ORG link : CVE-2023-23572


JSON object : View

Products Affected

epson

  • prifnw2_firmware
  • lp-s4200_firmware
  • prifnw2sac_firmware
  • lp-9800c
  • lp-s3000
  • prifnw2sac
  • lp-s6000_firmware
  • lp-9200b
  • lp-s5300r
  • prifnw1s_firmware
  • lp-8700ps3
  • lp-s7100
  • lp-9200ps2_firmware
  • lp-s5300
  • lp-s7500
  • lp-9600
  • lp-9200c
  • lp-s3500
  • prifnw7
  • lp-8500c
  • esnsb2
  • lp-s300n
  • lp-s9000_firmware
  • prifnw3
  • lp-s6500
  • prifnw1_firmware
  • prifnw2ac
  • lp-s310n
  • lp-s6500_firmware
  • lp-9600_firmware
  • lp-s6000
  • lp-s3000z_firmware
  • prifnw3s_firmware
  • prifnw2s
  • lp-s5500_firmware
  • lp-9600s_firmware
  • lp-8700ps3_firmware
  • lp-9200c_firmware
  • lp-8500c_firmware
  • lp-s7000_firmware
  • lp-s5300_firmware
  • lp-s8100
  • lp-s3000ps
  • prifnw7s
  • prifnw2
  • lp-s3000r_firmware
  • lp-s4500
  • lp-s9000
  • pa-w11g2_firmware
  • lp-s5000
  • lp-s300n_firmware
  • lp-9200ps3
  • lp-8200c_firmware
  • prifnw1
  • prifnw3s
  • lp-9200b_firmware
  • prifnw1s
  • pa-w11g2
  • lp-s4000_firmware
  • prifnw7u
  • prifnw6_firmware
  • lp-s310n_firmware
  • lp-s3000z
  • esifnw1_firmware
  • pa-w11g_firmware
  • lp-s3000_firmware
  • lp-9800c_firmware
  • esnsb2_firmware
  • prifnw3_firmware
  • esnsb1
  • lp-s7500_firmware
  • lp-s3500_firmware
  • lp-s8100_firmware
  • lp-s4200
  • lp-s3000r
  • lp-s4500_firmware
  • prifnw7_firmware
  • lp-s4000
  • lp-9200ps3_firmware
  • lp-s5300r_firmware
  • prifnw2s_firmware
  • prifnw6
  • lp-9300
  • lp-s3000ps_firmware
  • esifnw1
  • lp-s5000_firmware
  • prifnw7u_firmware
  • lp-9600s
  • pa-w11g
  • lp-s7100_firmware
  • lp-s5500
  • lp-s7500ps
  • lp-8200c
  • lp-s7000
  • prifnw7s_firmware
  • lp-9200ps2
  • prifnw2ac_firmware
  • lp-s7500ps_firmware
  • esnsb1_firmware
  • lp-9300_firmware
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')