{"id":58548,"date":"2024-07-30T19:49:41","date_gmt":"2024-07-30T16:49:41","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/179808\/epsonexpressionxp255-snmp.txt"},"modified":"2024-07-30T19:49:41","modified_gmt":"2024-07-30T16:49:41","slug":"epson-expression-home-xp255-20-08-fm10i8-snmpv1-public-community","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/epson-expression-home-xp255-20-08-fm10i8-snmpv1-public-community\/","title":{"rendered":"Epson Expression Home XP255 20.08.FM10I8 SNMPv1 Public Community"},"content":{"rendered":"[Suggested description]An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices.<br \/>With the SNMPv1 public community,<br \/>all values can be read, and with the epson community, all the<br \/>changeable values can be written\/updated, as demonstrated by<br \/>permanently disabling the network card or changing the DNS servers.<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n[Vulnerability Type]Insecure Permissions<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n[Vendor of Product]Epson<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n[Affected Product Code Base]Expression Home XP255 &#8211; 20.08.FM10I8<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n[Affected Component]SNMP agent<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n[Attack Type]Remote<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n[Impact Denial of Service]true<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n[Impact Escalation of Privileges]true<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n[Impact Information Disclosure]true<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n[Attack Vectors]The attacker must be able to connect to the devices on port 515\/UDP.<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n[Has vendor confirmed or acknowledged the vulnerability?]true<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n[Discoverer]Konrad Leszczynski, intern at Qbit in collaboration with the Dutch consumer organisation.<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n[Reference]https:\/\/epson.com\/Support\/sl\/s<\/p>\n<p>Use CVE-2019-20459.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[Suggested description]An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices.With the SNMPv1 public community,all values can be read, and with the epson community, all thechangeable values can be written\/updated, as demonstrated bypermanently disabling the network card or changing the DNS servers. &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212; [Vulnerability Type]Insecure Permissions &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212; [Vendor of Product]Epson &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212; [Affected Product Code &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-58548","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/58548","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=58548"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/58548\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=58548"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=58548"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=58548"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}