PT-2024-10735 · Epson · Epson Expression Home Xp255
Konrad Leszczynski
·
Published
2024-11-07
·
Updated
2024-11-10
·
CVE-2019-20459
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Epson Expression Home XP255 version 20.08.FM10I8
Description
An issue was discovered that allows all values to be read with the SNMPv1 public community, and with the epson community, all the changeable values can be written/updated. This can be demonstrated by permanently disabling the network card or changing the DNS servers.
Recommendations
For Epson Expression Home XP255 version 20.08.FM10I8, consider disabling the SNMPv1 public community and restricting access to the epson community to minimize the risk of exploitation. Update to the latest firmware and apply all recommended security patches to mitigate risks.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Epson Expression Home Xp255