PT-2024-10774 · Epson+1 · Epson Products+1

Jasper Nota

+3

·

Published

2024-11-07

·

Updated

2024-11-11

·

CVE-2020-11921

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lush 2 versions through 2020-02-25 Tk-star nan versions (affected versions not specified) Epson products versions (affected versions not specified) One2Track versions (affected versions not specified) Brother printers versions (affected versions not specified) Svakom Nan versions (affected versions not specified) Loven nan versions (affected versions not specified) Loven versions (affected versions not specified)
Description The issue is related to the lack of Bluetooth traffic encryption, allowing an attacker to hijack an ongoing Bluetooth connection and gain full control over the device. This vulnerability affects multiple products and versions, putting them at risk of exploitation. Users are urged to update to the latest version to mitigate risks. The vulnerability can lead to remote code execution.
Recommendations For Lush 2 versions through 2020-02-25, update to a version released after 2020-02-25 to mitigate the risk. For Tk-star nan, update to the latest version to mitigate risks. For Epson products, ensure your systems are updated to the latest firmware to mitigate potential threats. For One2Track, update to the latest release to mitigate risks. For Brother printers, update to the latest firmware immediately to protect your devices and disable unnecessary network services. For Svakom Nan, update to the latest version to mitigate risks. For Loven nan, update to the latest version and apply all recommended patches to mitigate risks. For Loven, update to the latest release to mitigate risks.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2020-11921

Affected Products

Brother Printers
Epson Products