ID

VAR-202407-2626


CVE

CVE-2019-20459


TITLE

Epson Expression Home XP255 20.08.FM10I8 SNMPv1 Public Community

Trust: 0.1

sources: PACKETSTORM: 179808

DESCRIPTION

An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. With the SNMPv1 public community, all values can be read, and with the epson community, all the changeable values can be written/updated, as demonstrated by permanently disabling the network card or changing the DNS servers. ------------------------------------------ [Vulnerability Type] Insecure Permissions ------------------------------------------ [Vendor of Product] Epson ------------------------------------------ [Affected Product Code Base] Expression Home XP255 - 20.08.FM10I8 ------------------------------------------ [Affected Component] SNMP agent ------------------------------------------ [Attack Type] Remote ------------------------------------------ [Impact Denial of Service] true ------------------------------------------ [Impact Escalation of Privileges] true ------------------------------------------ [Impact Information Disclosure] true ------------------------------------------ [Attack Vectors] The attacker must be able to connect to the devices on port 515/UDP. ------------------------------------------ [Has vendor confirmed or acknowledged the vulnerability?] true ------------------------------------------ [Discoverer] Konrad Leszczynski, intern at Qbit in collaboration with the Dutch consumer organisation. ------------------------------------------ [Reference] https://epson.com/Support/sl/s Use CVE-2019-20459

Trust: 0.99

sources: NVD: CVE-2019-20459 // PACKETSTORM: 179808

CVSS

SEVERITY

CVSSV2

CVSSV3

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2019-20459
value: HIGH

Trust: 1.0

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2019-20459
baseSeverity: HIGH
baseScore: 8.4
vectorString: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.5
impactScore: 5.9
version: 3.1

Trust: 1.0

sources: NVD: CVE-2019-20459

EXTERNAL IDS

db:NVDid:CVE-2019-20459

Trust: 1.2

db:OTHERid:NONE

Trust: 0.1

db:PACKETSTORMid:179808

Trust: 0.1

sources: OTHER: None // PACKETSTORM: 179808 // NVD: CVE-2019-20459

REFERENCES

url:https://epson.com/support/wa00826

Trust: 1.0

url:https://seclists.org/fulldisclosure/2024/jul/14

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2019-20459

Trust: 0.1

url:https://epson.com/support/sl/s

Trust: 0.1

sources: PACKETSTORM: 179808 // NVD: CVE-2019-20459

CREDITS

Willem Westerhof | Secura

Trust: 0.1

sources: OTHER: None

SOURCES

db:OTHERid: -
db:PACKETSTORMid:179808
db:NVDid:CVE-2019-20459

LAST UPDATE DATE

2025-01-30T21:21:19.654000+00:00


SOURCES UPDATE DATE

db:NVDid:CVE-2019-20459date:2024-11-08T19:01:03.880

SOURCES RELEASE DATE

db:OTHERid: - date:2024-07-26T13:11:06
db:PACKETSTORMid:179808date:2024-07-30T12:35:43
db:NVDid:CVE-2019-20459date:2024-11-07T18:15:15.227