Insecure Initial Password Configuration in Epson WebConfig Vulnerability

Vulnerability Reference: CVE-2024-47295

Description:

If the administrator password on the affected product is left blank and the device is accessed via WebConfig, it's possible to setup an administrator password on the device.

Impact:

A third party may take control of the device and operate it remotely. Currently, there are no reports of attacks exploiting this vulnerability.

Solution:

To ensure the security of your Epson product, please configure an administrator password. As a general rule to help secure all devices, end-users and their administrators should always implement and maintain industry-standard security controls and practices in setting up and managing their networks. Those practices include immediately replacing default passwords with strong passwords and connecting projectors behind a firewall. For more information on securing your Epson product visit our Security Guidebook.

Note:

This vulnerability only applies to legacy devices and a password should be created if there is no password already. Current new devices purchased in Europe are not affected.

Affected Products

 

Inkjet Printers

 

Laser Printers

 

Impact Printers

 

Large Format Printers

 

Photo Printers

 

Mini Lab

 

Scanners

 

Network Interface Products