Headline
Epson Expression Home XP255 20.08.FM10I8 SNMPv1 Public Community
An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. With the SNMPv1 public community, all values can be read, and with the epson community, all the changeable values can be written/updated, as demonstrated by permanently disabling the network card or changing the DNS servers.
[Suggested description]
An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices.
With the SNMPv1 public community,
all values can be read, and with the epson community, all the
changeable values can be written/updated, as demonstrated by
permanently disabling the network card or changing the DNS servers.
[Vulnerability Type]
Insecure Permissions
[Vendor of Product]
Epson
[Affected Product Code Base]
Expression Home XP255 - 20.08.FM10I8
[Affected Component]
SNMP agent
[Attack Type]
Remote
[Impact Denial of Service]
true
[Impact Escalation of Privileges]
true
[Impact Information Disclosure]
true
[Attack Vectors]
The attacker must be able to connect to the devices on port 515/UDP.
[Has vendor confirmed or acknowledged the vulnerability?]
true
[Discoverer]
Konrad Leszczynski, intern at Qbit in collaboration with the Dutch consumer organisation.
[Reference]
https://epson.com/Support/sl/s
Use CVE-2019-20459.