CVE-2018-5550
Last modified
CVE-2018-5550 is a vulnerability of currently unknown severity. Versions of Epson AirPrint released prior to January 19, 2018 contain a reflective cross-site scripting (XSS) vulnerability, which can allow untrusted users on the network to hijack a session cookie or perform other reflected XSS attacks on a currently logged-on user.. EPSS estimates a 37.46% chance of exploitation in the next 30 days.
Description
Versions of Epson AirPrint released prior to January 19, 2018 contain a reflective cross-site scripting (XSS) vulnerability, which can allow untrusted users on the network to hijack a session cookie or perform other reflected XSS attacks on a currently logged-on user.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Epson | Airprint | < 1-19-2018 |
References
- https://blog.rapid7.com/2018/02/08/r7-2017-28-epson-airprint-xss-cve-2018-5550/Exploit, Third Party Advisory
- https://epson.com/support/wa00860Vendor Advisory
- https://blog.rapid7.com/2018/02/08/r7-2017-28-epson-airprint-xss-cve-2018-5550/Exploit, Third Party Advisory
- https://epson.com/support/wa00860Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5550?
How severe is CVE-2018-5550?
How do I fix CVE-2018-5550?
Are you affected by CVE-2018-5550?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
