CVE-2023-23572

C

ross-site scripting vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers/network interface via a web browser. According to SEIKO EPSON CORPORATION, it is also called as Remote Manager in some products. Web Config is pre-installed in some printers/network interface provided by SEIKO EPSON CORPORATION. For the details of the affected product names/model numbers, refer to the information provided by the vendor.

References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:epson:lp-9200ps2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-9200ps2:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:epson:lp-9200ps3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-9200ps3:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:epson:lp-8200c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-8200c:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:epson:lp-9600_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-9600:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:epson:lp-9600s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-9600s:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:epson:lp-9300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-9300:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:epson:lp-8500c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-8500c:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:epson:lp-8700ps3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-8700ps3:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:epson:lp-9800c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-9800c:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:epson:lp-s5500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s5500:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:epson:lp-9200b_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-9200b:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:epson:lp-9200c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-9200c:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:epson:lp-s4500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s4500:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:epson:lp-s6500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s6500:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:epson:lp-s7000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s7000:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:epson:lp-s5000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s5000:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:epson:lp-s4000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s4000:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:epson:lp-s6000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s6000:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:epson:lp-s5300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s5300:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:epson:lp-s5300r_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s5300r:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:epson:lp-s300n_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s300n:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:epson:lp-s310n_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s310n:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:epson:lp-s3000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s3000:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:epson:lp-s3000r_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s3000r:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:epson:lp-s3000z_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s3000z:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:epson:lp-s3000ps_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s3000ps:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:epson:lp-s7500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s7500:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:epson:lp-s7500ps_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s7500ps:-:*:*:*:*:*:*:*

Configuration 29 (hide)

AND
cpe:2.3:o:epson:lp-s3500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s3500:-:*:*:*:*:*:*:*

Configuration 30 (hide)

AND
cpe:2.3:o:epson:lp-s4200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s4200:-:*:*:*:*:*:*:*

Configuration 31 (hide)

AND
cpe:2.3:o:epson:lp-s9000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s9000:-:*:*:*:*:*:*:*

Configuration 32 (hide)

AND
cpe:2.3:o:epson:lp-s7100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s7100:-:*:*:*:*:*:*:*

Configuration 33 (hide)

AND
cpe:2.3:o:epson:lp-s8100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s8100:-:*:*:*:*:*:*:*

Configuration 34 (hide)

AND
cpe:2.3:o:epson:prifnw1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:prifnw1:-:*:*:*:*:*:*:*

Configuration 35 (hide)

AND
cpe:2.3:o:epson:prifnw1s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:prifnw1s:-:*:*:*:*:*:*:*

Configuration 36 (hide)

AND
cpe:2.3:o:epson:prifnw2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:prifnw2:-:*:*:*:*:*:*:*

Configuration 37 (hide)

AND
cpe:2.3:o:epson:prifnw2ac_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:prifnw2ac:-:*:*:*:*:*:*:*

Configuration 38 (hide)

AND
cpe:2.3:o:epson:prifnw2s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:prifnw2s:-:*:*:*:*:*:*:*

Configuration 39 (hide)

AND
cpe:2.3:o:epson:prifnw2sac_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:prifnw2sac:-:*:*:*:*:*:*:*

Configuration 40 (hide)

AND
cpe:2.3:o:epson:prifnw3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:prifnw3:-:*:*:*:*:*:*:*

Configuration 41 (hide)

AND
cpe:2.3:o:epson:prifnw3s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:prifnw3s:-:*:*:*:*:*:*:*

Configuration 42 (hide)

AND
cpe:2.3:o:epson:prifnw6_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:prifnw6:-:*:*:*:*:*:*:*

Configuration 43 (hide)

AND
cpe:2.3:o:epson:prifnw7_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:prifnw7:-:*:*:*:*:*:*:*

Configuration 44 (hide)

AND
cpe:2.3:o:epson:prifnw7u_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:prifnw7u:-:*:*:*:*:*:*:*

Configuration 45 (hide)

AND
cpe:2.3:o:epson:prifnw7s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:prifnw7s:-:*:*:*:*:*:*:*

Configuration 46 (hide)

AND
cpe:2.3:o:epson:pa-w11g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:pa-w11g:-:*:*:*:*:*:*:*

Configuration 47 (hide)

AND
cpe:2.3:o:epson:pa-w11g2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:pa-w11g2:-:*:*:*:*:*:*:*

Configuration 48 (hide)

AND
cpe:2.3:o:epson:esnsb1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:esnsb1:-:*:*:*:*:*:*:*

Configuration 49 (hide)

AND
cpe:2.3:o:epson:esnsb2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:esnsb2:-:*:*:*:*:*:*:*

Configuration 50 (hide)

AND
cpe:2.3:o:epson:esifnw1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:esifnw1:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:46

Type Values Removed Values Added
References () https://jvn.jp/en/jp/JVN82424996/ - Third Party Advisory () https://jvn.jp/en/jp/JVN82424996/ - Third Party Advisory
References () https://www.epson.jp/support/misc_t/230308_oshirase.htm - Mitigation, Vendor Advisory () https://www.epson.jp/support/misc_t/230308_oshirase.htm - Mitigation, Vendor Advisory

Information

Published : 2023-04-11 09:15

Updated : 2025-02-11 16:15


NVD link : CVE-2023-23572

Mitre link : CVE-2023-23572

CVE.ORG link : CVE-2023-23572


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')