NVD Vulnerability Detail
Search Exploit, PoC
CVE-2018-0689
Summary

HTTP header injection vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780N firmware versions released prior to 2018 March 13, EP-10VA firmware versions released prior to 2017 September 4, EP-30VA firmware versions released prior to 2017 June 19, EP-707A firmware versions released prior to 2017 August 1, EP-708A firmware versions released prior to 2017 August 7, EP-709A firmware versions released prior to 2017 June 12, EP-777A firmware versions released prior to 2017 August 1, EP-807AB/AW/AR firmware versions released prior to 2017 August 1, EP-808AB/AW/AR firmware versions released prior to 2017 August 7, EP-879AB/AW/AR firmware versions released prior to 2017 June 12, EP-907F firmware versions released prior to 2017 August 1, EP-977A3 firmware versions released prior to 2017 August 1, EP-978A3 firmware versions released prior to 2017 August 7, EP-979A3 firmware versions released prior to 2017 June 12, EP-M570T firmware versions released prior to 2017 September 6, EW-M5071FT firmware versions released prior to 2017 November 2, EW-M660FT firmware versions released prior to 2018 April 19, EW-M770T firmware versions released prior to 2017 September 6, PF-70 firmware versions released prior to 2018 April 20, PF-71 firmware versions released prior to 2017 July 18, PF-81 firmware versions released prior to 2017 September 14, PX-048A firmware versions released prior to 2017 July 4, PX-049A firmware versions released prior to 2017 September 11, PX-437A firmware versions released prior to 2017 July 24, PX-M350F firmware versions released prior to 2018 February 23, PX-M5040F firmware versions released prior to 2017 November 20, PX-M5041F firmware versions released prior to 2017 November 20, PX-M650A firmware versions released prior to 2017 October 17, PX-M650F firmware versions released prior to 2017 October 17, PX-M680F firmware versions released prior to 2017 June 29, PX-M7050F firmware versions released prior to 2017 October 13, PX-M7050FP firmware versions released prior to 2017 October 13, PX-M7050FX firmware versions released prior to 2017 November 7, PX-M7070FX firmware versions released prior to 2017 April 27, PX-M740F firmware versions released prior to 2017 December 4, PX-M741F firmware versions released prior to 2017 December 4, PX-M780F firmware versions released prior to 2017 June 29, PX-M781F firmware versions released prior to 2017 June 27, PX-M840F firmware versions released prior to 2017 November 16, PX-M840FX firmware versions released prior to 2017 December 8, PX-M860F firmware versions released prior to 2017 October 25, PX-S05B/W firmware versions released prior to 2018 March 9, PX-S350 firmware versions released prior to 2018 February 23, PX-S5040 firmware versions released prior to 2017 November 20, PX-S7050 firmware versions released prior to 2018 February 21, PX-S7050PS firmware versions released prior to 2018 February 21, PX-S7050X firmware versions released prior to 2017 November 7, PX-S7070X firmware versions released prior to 2017 April 27, PX-S740 firmware versions released prior to 2017 December 3, PX-S840 firmware versions released prior to 2017 November 16, PX-S840X firmware versions released prior to 2017 December 8, PX-S860 firmware versions released prior to 2017 December 7) may allow a remote attackers to lead a user to a phishing site or execute an arbitrary script on the user's web browser.

Publication Date Jan. 10, 2019, 8:29 a.m.
Registration Date March 1, 2021, 6:37 p.m.
Last Update Nov. 21, 2024, 12:38 p.m.
CVSS3.0 : HIGH
スコア 8.8
Vector CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
攻撃元区分(AV) ネットワーク
攻撃条件の複雑さ(AC)
攻撃に必要な特権レベル(PR) 不要
利用者の関与(UI)
影響の想定範囲(S) 変更なし
機密性への影響(C)
完全性への影響(I)
可用性への影響(A)
CVSS2.0 : MEDIUM
Score 6.8
Vector AV:N/AC:M/Au:N/C:P/I:P/A:P
攻撃元区分(AV) ネットワーク
攻撃条件の複雑さ(AC)
攻撃前の認証要否(Au) 不要
機密性への影響(C)
完全性への影響(I)
可用性への影響(A)
Get all privileges. いいえ
Get user privileges いいえ
Get other privileges いいえ
User operation required はい
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:o:epson:ds-570w_firmware:*:*:*:*:*:*:*:* 2018-03-13
execution environment
1 cpe:2.3:h:epson:ds-570w:-:*:*:*:*:*:*:*
Configuration2 or higher or less more than less than
cpe:2.3:o:epson:ds-780n_firmware:*:*:*:*:*:*:*:* 2018-03-13
execution environment
1 cpe:2.3:h:epson:ds-780n:-:*:*:*:*:*:*:*
Configuration3 or higher or less more than less than
cpe:2.3:o:epson:ep-10va_firmware:*:*:*:*:*:*:*:* 2017-09-04
execution environment
1 cpe:2.3:h:epson:ep-10va:-:*:*:*:*:*:*:*
Configuration4 or higher or less more than less than
cpe:2.3:o:epson:ep-30va_firmware:*:*:*:*:*:*:*:* 2017-06-19
execution environment
1 cpe:2.3:h:epson:ep-30va:-:*:*:*:*:*:*:*
Configuration5 or higher or less more than less than
cpe:2.3:o:epson:ep-707a_firmware:*:*:*:*:*:*:*:* 2017-08-01
execution environment
1 cpe:2.3:h:epson:ep-707a:-:*:*:*:*:*:*:*
Configuration6 or higher or less more than less than
cpe:2.3:o:epson:ep-708a_firmware:*:*:*:*:*:*:*:* 2017-08-07
execution environment
1 cpe:2.3:h:epson:ep-708a:-:*:*:*:*:*:*:*
Configuration7 or higher or less more than less than
cpe:2.3:o:epson:ep-709a_firmware:*:*:*:*:*:*:*:* 2017-06-12
execution environment
1 cpe:2.3:h:epson:ep-709a:-:*:*:*:*:*:*:*
Configuration8 or higher or less more than less than
cpe:2.3:o:epson:ep-777a_firmware:*:*:*:*:*:*:*:* 2017-08-01
execution environment
1 cpe:2.3:h:epson:ep-777a:-:*:*:*:*:*:*:*
Configuration9 or higher or less more than less than
cpe:2.3:o:epson:ep-807ab_firmware:*:*:*:*:*:*:*:* 2017-08-01
execution environment
1 cpe:2.3:h:epson:ep-807ab:-:*:*:*:*:*:*:*
Configuration10 or higher or less more than less than
cpe:2.3:o:epson:ep-807aw_firmware:*:*:*:*:*:*:*:* 2017-08-01
execution environment
1 cpe:2.3:h:epson:ep-807aw:-:*:*:*:*:*:*:*
Configuration11 or higher or less more than less than
cpe:2.3:o:epson:ep-807ar_firmware:*:*:*:*:*:*:*:* 2017-08-01
execution environment
1 cpe:2.3:h:epson:ep-807ar:-:*:*:*:*:*:*:*
Configuration12 or higher or less more than less than
cpe:2.3:o:epson:ep-808ab_firmware:*:*:*:*:*:*:*:* 2017-08-07
execution environment
1 cpe:2.3:h:epson:ep-808ab:-:*:*:*:*:*:*:*
Configuration13 or higher or less more than less than
cpe:2.3:o:epson:ep-808aw_firmware:*:*:*:*:*:*:*:* 2017-08-07
execution environment
1 cpe:2.3:h:epson:ep-808aw:-:*:*:*:*:*:*:*
Configuration14 or higher or less more than less than
cpe:2.3:o:epson:ep-808ar_firmware:*:*:*:*:*:*:*:* 2017-08-07
execution environment
1 cpe:2.3:h:epson:ep-808ar:-:*:*:*:*:*:*:*
Configuration15 or higher or less more than less than
cpe:2.3:o:epson:ep-879ab_firmware:*:*:*:*:*:*:*:* 2017-06-12
execution environment
1 cpe:2.3:h:epson:ep-879ab:-:*:*:*:*:*:*:*
Configuration16 or higher or less more than less than
cpe:2.3:o:epson:ep-879aw_firmware:*:*:*:*:*:*:*:* 2017-06-12
execution environment
1 cpe:2.3:h:epson:ep-879aw:-:*:*:*:*:*:*:*
Configuration17 or higher or less more than less than
cpe:2.3:o:epson:ep-879ar_firmware:*:*:*:*:*:*:*:* 2017-06-12
execution environment
1 cpe:2.3:h:epson:ep-879ar:-:*:*:*:*:*:*:*
Configuration18 or higher or less more than less than
cpe:2.3:o:epson:ep-907f_firmware:*:*:*:*:*:*:*:* 2017-08-01
execution environment
1 cpe:2.3:h:epson:ep-907f:-:*:*:*:*:*:*:*
Configuration19 or higher or less more than less than
cpe:2.3:o:epson:ep-977a3_firmware:*:*:*:*:*:*:*:* 2017-08-01
execution environment
1 cpe:2.3:h:epson:ep-977a3:-:*:*:*:*:*:*:*
Configuration20 or higher or less more than less than
cpe:2.3:o:epson:ep-978a3_firmware:*:*:*:*:*:*:*:* 2017-08-07
execution environment
1 cpe:2.3:h:epson:ep-978a3:-:*:*:*:*:*:*:*
Configuration21 or higher or less more than less than
cpe:2.3:o:epson:ep-979a3_firmware:*:*:*:*:*:*:*:* 2017-06-12
execution environment
1 cpe:2.3:h:epson:ep-979a3:-:*:*:*:*:*:*:*
Configuration22 or higher or less more than less than
cpe:2.3:o:epson:ep-m570t_firmware:*:*:*:*:*:*:*:* 2017-09-06
execution environment
1 cpe:2.3:h:epson:ep-m570t:-:*:*:*:*:*:*:*
Configuration23 or higher or less more than less than
cpe:2.3:o:epson:ew-m5071ft_firmware:*:*:*:*:*:*:*:* 2017-11-02
execution environment
1 cpe:2.3:h:epson:ew-m5071ft:-:*:*:*:*:*:*:*
Configuration24 or higher or less more than less than
cpe:2.3:o:epson:ew-m660ft_firmware:*:*:*:*:*:*:*:* 2018-04-19
execution environment
1 cpe:2.3:h:epson:ew-m660ft:-:*:*:*:*:*:*:*
Configuration25 or higher or less more than less than
cpe:2.3:o:epson:ew-m770t_firmware:*:*:*:*:*:*:*:* 2017-09-06
execution environment
1 cpe:2.3:h:epson:ew-m770t:-:*:*:*:*:*:*:*
Configuration26 or higher or less more than less than
cpe:2.3:o:epson:pf-70_firmware:*:*:*:*:*:*:*:* 2018-04-20
execution environment
1 cpe:2.3:h:epson:pf-70:-:*:*:*:*:*:*:*
Configuration27 or higher or less more than less than
cpe:2.3:o:epson:pf-71_firmware:*:*:*:*:*:*:*:* 2017-07-18
execution environment
1 cpe:2.3:h:epson:pf-71:-:*:*:*:*:*:*:*
Configuration28 or higher or less more than less than
cpe:2.3:o:epson:pf-81_firmware:*:*:*:*:*:*:*:* 2017-09-14
execution environment
1 cpe:2.3:h:epson:pf-81:-:*:*:*:*:*:*:*
Configuration29 or higher or less more than less than
cpe:2.3:o:epson:px-048a_firmware:*:*:*:*:*:*:*:* 2017-07-04
execution environment
1 cpe:2.3:h:epson:px-048a:-:*:*:*:*:*:*:*
Configuration30 or higher or less more than less than
cpe:2.3:o:epson:px-049a_firmware:*:*:*:*:*:*:*:* 2017-09-11
execution environment
1 cpe:2.3:h:epson:px-049a:-:*:*:*:*:*:*:*
Configuration31 or higher or less more than less than
cpe:2.3:o:epson:px-437a_firmware:*:*:*:*:*:*:*:* 2017-07-24
execution environment
1 cpe:2.3:h:epson:px-437a:-:*:*:*:*:*:*:*
Configuration32 or higher or less more than less than
cpe:2.3:o:epson:px-m350f_firmware:*:*:*:*:*:*:*:* 2018-02-23
execution environment
1 cpe:2.3:h:epson:px-m350f:-:*:*:*:*:*:*:*
Configuration33 or higher or less more than less than
cpe:2.3:o:epson:px-m5040f_firmware:*:*:*:*:*:*:*:* 2017-11-20
execution environment
1 cpe:2.3:h:epson:px-m5040f:-:*:*:*:*:*:*:*
Configuration34 or higher or less more than less than
cpe:2.3:o:epson:px-m5041f_firmware:*:*:*:*:*:*:*:* 2017-11-20
execution environment
1 cpe:2.3:h:epson:px-m5041f:-:*:*:*:*:*:*:*
Configuration35 or higher or less more than less than
cpe:2.3:o:epson:px-m650a_firmware:*:*:*:*:*:*:*:* 2017-10-17
execution environment
1 cpe:2.3:h:epson:px-m650a:-:*:*:*:*:*:*:*
Configuration36 or higher or less more than less than
cpe:2.3:o:epson:px-m650f_firmware:*:*:*:*:*:*:*:* 2017-10-17
execution environment
1 cpe:2.3:h:epson:px-m650f:-:*:*:*:*:*:*:*
Configuration37 or higher or less more than less than
cpe:2.3:o:epson:px-m680f_firmware:*:*:*:*:*:*:*:* 2017-06-29
execution environment
1 cpe:2.3:h:epson:px-m680f:-:*:*:*:*:*:*:*
Configuration38 or higher or less more than less than
cpe:2.3:o:epson:px-m7050f_firmware:*:*:*:*:*:*:*:* 2017-10-13
execution environment
1 cpe:2.3:h:epson:px-m7050f:-:*:*:*:*:*:*:*
Configuration39 or higher or less more than less than
cpe:2.3:o:epson:px-m7050fp_firmware:*:*:*:*:*:*:*:* 2017-10-13
execution environment
1 cpe:2.3:h:epson:px-m7050fp:-:*:*:*:*:*:*:*
Configuration40 or higher or less more than less than
cpe:2.3:o:epson:px-m7050fx_firmware:*:*:*:*:*:*:*:* 2017-11-07
execution environment
1 cpe:2.3:h:epson:px-m7050fx:-:*:*:*:*:*:*:*
Configuration41 or higher or less more than less than
cpe:2.3:o:epson:px-m7070fx_firmware:*:*:*:*:*:*:*:* 2017-04-27
execution environment
1 cpe:2.3:h:epson:px-m7070fx:-:*:*:*:*:*:*:*
Configuration42 or higher or less more than less than
cpe:2.3:o:epson:px-m740f_firmware:*:*:*:*:*:*:*:* 2017-06-29
execution environment
1 cpe:2.3:h:epson:px-m740f:-:*:*:*:*:*:*:*
Configuration43 or higher or less more than less than
cpe:2.3:o:epson:px-m781f_firmware:*:*:*:*:*:*:*:* 2017-06-27
execution environment
1 cpe:2.3:h:epson:px-m781f:-:*:*:*:*:*:*:*
Configuration44 or higher or less more than less than
cpe:2.3:o:epson:px-m840f_firmware:*:*:*:*:*:*:*:* 2017-11-16
execution environment
1 cpe:2.3:h:epson:px-m840f:-:*:*:*:*:*:*:*
Configuration45 or higher or less more than less than
cpe:2.3:o:epson:px-m840fx_firmware:*:*:*:*:*:*:*:* 2017-12-08
execution environment
1 cpe:2.3:h:epson:px-m840fx:-:*:*:*:*:*:*:*
Configuration46 or higher or less more than less than
cpe:2.3:o:epson:px-m860f_firmware:*:*:*:*:*:*:*:* 2017-10-25
execution environment
1 cpe:2.3:h:epson:px-m860f:-:*:*:*:*:*:*:*
Configuration47 or higher or less more than less than
cpe:2.3:o:epson:px-s05b_firmware:*:*:*:*:*:*:*:* 2018-03-09
execution environment
1 cpe:2.3:h:epson:px-s05b:-:*:*:*:*:*:*:*
Configuration48 or higher or less more than less than
cpe:2.3:o:epson:px-s05w_firmware:*:*:*:*:*:*:*:* 2018-03-09
execution environment
1 cpe:2.3:h:epson:px-s05w:-:*:*:*:*:*:*:*
Configuration49 or higher or less more than less than
cpe:2.3:o:epson:px-s350_firmware:*:*:*:*:*:*:*:* 2018-02-23
execution environment
1 cpe:2.3:h:epson:px-s350:-:*:*:*:*:*:*:*
Configuration50 or higher or less more than less than
cpe:2.3:o:epson:px-s5040_firmware:*:*:*:*:*:*:*:* 2017-11-20
execution environment
1 cpe:2.3:h:epson:px-s5040:-:*:*:*:*:*:*:*
Configuration51 or higher or less more than less than
cpe:2.3:o:epson:px-s7050_firmware:*:*:*:*:*:*:*:* 2018-02-21
execution environment
1 cpe:2.3:h:epson:px-s7050:-:*:*:*:*:*:*:*
Configuration52 or higher or less more than less than
cpe:2.3:o:epson:px-s7050ps_firmware:*:*:*:*:*:*:*:* 2018-02-21
execution environment
1 cpe:2.3:h:epson:px-s7050ps:-:*:*:*:*:*:*:*
Configuration53 or higher or less more than less than
cpe:2.3:o:epson:px-s7050x_firmware:*:*:*:*:*:*:*:* 2017-11-07
execution environment
1 cpe:2.3:h:epson:px-s7050x:-:*:*:*:*:*:*:*
Configuration54 or higher or less more than less than
cpe:2.3:o:epson:px-s7070x_firmware:*:*:*:*:*:*:*:* 2017-04-27
execution environment
1 cpe:2.3:h:epson:px-s7070x:-:*:*:*:*:*:*:*
Configuration55 or higher or less more than less than
cpe:2.3:o:epson:px-s740_firmware:*:*:*:*:*:*:*:* 2017-12-03
execution environment
1 cpe:2.3:h:epson:px-s740:-:*:*:*:*:*:*:*
Configuration56 or higher or less more than less than
cpe:2.3:o:epson:px-s840_firmware:*:*:*:*:*:*:*:* 2017-11-16
execution environment
1 cpe:2.3:h:epson:px-s840:-:*:*:*:*:*:*:*
Configuration57 or higher or less more than less than
cpe:2.3:o:epson:px-s840x_firmware:*:*:*:*:*:*:*:* 2017-12-08
execution environment
1 cpe:2.3:h:epson:px-s840x:-:*:*:*:*:*:*:*
Configuration58 or higher or less more than less than
cpe:2.3:o:epson:px-s860_firmware:*:*:*:*:*:*:*:* 2017-12-07
execution environment
1 cpe:2.3:h:epson:px-s860:-:*:*:*:*:*:*:*
Related information, measures and tools
Common Vulnerabilities List