PT-2024-10735 · Epson · Epson Expression Home Xp255

Konrad Leszczynski

·

Published

2024-11-07

·

Updated

2024-11-10

·

CVE-2019-20459

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Epson Expression Home XP255 version 20.08.FM10I8
Description An issue was discovered that allows all values to be read with the SNMPv1 public community, and with the epson community, all the changeable values can be written/updated. This can be demonstrated by permanently disabling the network card or changing the DNS servers.
Recommendations For Epson Expression Home XP255 version 20.08.FM10I8, consider disabling the SNMPv1 public community and restricting access to the epson community to minimize the risk of exploitation. Update to the latest firmware and apply all recommended security patches to mitigate risks.

Fix

Related Identifiers

CVE-2019-20459

Affected Products

Epson Expression Home Xp255