Impact
The vulnerability arises because several SEIKO EPSON printers and scanners ship with revoked root certificates. A compromised certificate enables an attacker engaged in a man‑in‑the‑middle attack to capture the data transmitted between the device and its client or server. The impact is loss of confidentiality of all data flowing through the affected device, but does not directly provide a path to execute code or modify device firmware.
Affected Systems
The flaw affects multiple SEIKO EPSON printers and scanners as listed by the vendor; specific models and firmware versions are detailed on Epson’s security advisory, but the set of affected devices includes both printers and scanners from SEIKO EPSON.
Risk and Exploitability
The CVSS score is 6.3, indicating a moderate severity. EPSS data is unavailable, so the exact exploitation probability is unknown. The flaw is not listed in CISA’s KEV catalog, suggesting no publicly documented exploits at this time. The likely attack vector is a hostile network segment that can intercept or inject traffic to the device; an attacker would need network access to the Ethernet or Wi‑Fi interface used by the device.
OpenCVE Enrichment