Insecure Initial Password Configuration in Epson WebConfig Vulnerability

 

Vulnerability Reference: CVE-2024-47295

Description:If the administrator password on the affected product is left blank (not set) and the device is accessed via Web Config, it’s possible to setup an administrator password on the device.

Impact:This may allow a malicious third party to take over the device and operate it remotely. Currently, there are no reports of attacks exploiting this vulnerability.

Solution:
Connecting to Internet
The product should not be directly connected to the Internet and should be installed in a network protected by a firewall.


Administrator Password
Set an administrator password during the initial setup of the device. Password should be 8 characters or more, consist of upper/lower case, alphanumeric and symbols.
For more information on securing your Epson product, visit our Security Guidebook
 
 
 

Affected Products

DLQ-3500II
DLQ-3500IIN
LQ-2090II
LQ-2090IIN
LQ-590II
LQ-590IIN

Epson ME Office 82WD
Epson ME Office 900WD
Epson ME Office 960FWD
Epson Stylus Photo TX720WD
FX-2175II
FX-2175IIN
FX-2190II
FX-2190IIN
L14150
L1455
L15150
L15160
L15180
L3150
L3156
L355
L365
L385
L405
L4150
L4160
L455
L485
L5190
L550
L555
L565
L605
L6160
L6170
L6190
L6460
L6490
L655
L6550
L6580
L805
M100
M1120
M1170
M15140
M15180
M200
M2170
M3170
ME-301
PM-520
WF-100
WF-2631
WF-2651
WF-2661
WF-2851
WF-2861
WF-3521
WF-3721
WF-5111
WF-5621
WF-6091
WF-7011
WF-7111
WF-7511
WF-7611
WF-7711
WF-C17590
WF-C20590
WF-C20600
WF-C20750
WF-C21000
WF-C5290
WF-C5790
WF-C579R
WF-C869R
WF-C878R
WF-C879R
WF-M20590
WF-M21000
WF-R8591
WP-4011
WP-4091
WP-4511
WP-4521
XP-202
XP-2101
XP-225
XP-245
XP-402
XP-4101
XP-422
XP-442

SC-B6000 Series
SC-B7000 Series
SC-B9000 Series
SC-F100 Series
SC-F10000 Series
SC-F10000H Series
SC-F2000 Series
SC-F2100 Series
SC-F3000 Series
SC-F500 Series
SC-F6000 Series
SC-F6200 Series
SC-F6300 Series
SC-F7000 Series
SC-F7100 Series
SC-F7200 Series
SC-F9200 Series
SC-F9300 Series
SC-F9400 Series
SC-F9400H Series
SC-P10000 Series
SC-P20000 Series
SC-P5000 Series
SC-P6000 Series
SC-P7000 Series
SC-P7500 Series
SC-P8000 Series
SC-P9000 Series
SC-P9500 Series
SC-R5000 Series
SC-R5000L Series
SC-S30600 Series
SC-S40600 Series
SC-S50600 Series
SC-S60600 Series
SC-S60600L Series
SC-S70600 Series
SC-S80600 Series
SC-S80600L Series
SC-T3100/T3100N Series
SC-T3100M Series
SC-T3100X Series
SC-T3200 Series
SC-T3400/T3400N Series
SC-T3405/T3405N Series
SC-T5100/T5100N Series
SC-T5100M Series
SC-T5200 Series
SC-T5200D Series
SC-T5400 Series
SC-T5400M Series
SC-T5405 Series
SC-T7200 Series
SC-T7200D Series
StylusPro4900
StylusPro7900
StylusPro9860
StylusPro9900
StylusProGS6000

AL-C300DN
AL-C500DN
AL-C9500DN
AL-M300DN
AL-M310DN
AL-M320DN
AL-M400DN
AL-M8100DN
AL-M8150DN
EPL-N2000
EPL-N2050
EPL-N2050+
EPL-N2750
EPL-N3000
EPL-N4000
EPL-N4000+
Epson AcuLaser C1100
Epson AcuLaser C1100N
Epson AcuLaser C2000
Epson AcuLaser C2600N
Epson AcuLaser C3800DN
Epson AcuLaser C3800N
Epson AcuLaser C4000
Epson AcuLaser C4100
Epson AcuLaser C4200DN
Epson AcuLaser C8500
Epson AcuLaser C9100
Epson AcuLaser C9200N
Epson AcuLaser C9300N
Epson AcuLaser CX11N
Epson AcuLaser CX11NF
Epson AcuLaser M2010D
Epson AcuLaser M2010DN
Epson AcuLaser M2310D
Epson AcuLaser M2310DN
Epson AcuLaser M2410DN
Epson AcuLaser M4000N
Epson AcuLaser M7000N

SL-D700

EpsonNet 10 Base 2/T Int. Print Server
EpsonNet 10/100 Base Tx Ext. Print Server
EpsonNet 10/100 Base Tx Int. Print Server
EpsonNet 10/100 Base Tx Int. Print Server 2
EpsonNet 10/100 Base Tx Int. Print Server 5
EpsonNet 802.11b Wireless Ext. Print Server

StylusPro3885

DS-360W
DS-570W
DS-570WII
DS-730N
DS-780N
ES-580W