CVE-2018-0688

Open redirect vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780N firmware versions released prior to 2018 March 13, EP-10VA firmware versions released prior to 2017 September 4, EP-30VA firmware versions released prior to 2017 June 19, EP-707A firmware versions released prior to 2017 August 1, EP-708A firmware versions released prior to 2017 August 7, EP-709A firmware versions released prior to 2017 June 12, EP-777A firmware versions released prior to 2017 August 1, EP-807AB/AW/AR firmware versions released prior to 2017 August 1, EP-808AB/AW/AR firmware versions released prior to 2017 August 7, EP-879AB/AW/AR firmware versions released prior to 2017 June 12, EP-907F firmware versions released prior to 2017 August 1, EP-977A3 firmware versions released prior to 2017 August 1, EP-978A3 firmware versions released prior to 2017 August 7, EP-979A3 firmware versions released prior to 2017 June 12, EP-M570T firmware versions released prior to 2017 September 6, EW-M5071FT firmware versions released prior to 2017 November 2, EW-M660FT firmware versions released prior to 2018 April 19, EW-M770T firmware versions released prior to 2017 September 6, PF-70 firmware versions released prior to 2018 April 20, PF-71 firmware versions released prior to 2017 July 18, PF-81 firmware versions released prior to 2017 September 14, PX-048A firmware versions released prior to 2017 July 4, PX-049A firmware versions released prior to 2017 September 11, PX-437A firmware versions released prior to 2017 July 24, PX-M350F firmware versions released prior to 2018 February 23, PX-M5040F firmware versions released prior to 2017 November 20, PX-M5041F firmware versions released prior to 2017 November 20, PX-M650A firmware versions released prior to 2017 October 17, PX-M650F firmware versions released prior to 2017 October 17, PX-M680F firmware versions released prior to 2017 June 29, PX-M7050F firmware versions released prior to 2017 October 13, PX-M7050FP firmware versions released prior to 2017 October 13, PX-M7050FX firmware versions released prior to 2017 November 7, PX-M7070FX firmware versions released prior to 2017 April 27, PX-M740F firmware versions released prior to 2017 December 4, PX-M741F firmware versions released prior to 2017 December 4, PX-M780F firmware versions released prior to 2017 June 29, PX-M781F firmware versions released prior to 2017 June 27, PX-M840F firmware versions released prior to 2017 November 16, PX-M840FX firmware versions released prior to 2017 December 8, PX-M860F firmware versions released prior to 2017 October 25, PX-S05B/W firmware versions released prior to 2018 March 9, PX-S350 firmware versions released prior to 2018 February 23, PX-S5040 firmware versions released prior to 2017 November 20, PX-S7050 firmware versions released prior to 2018 February 21, PX-S7050PS firmware versions released prior to 2018 February 21, PX-S7050X firmware versions released prior to 2017 November 7, PX-S7070X firmware versions released prior to 2017 April 27, PX-S740 firmware versions released prior to 2017 December 3, PX-S840 firmware versions released prior to 2017 November 16, PX-S840X firmware versions released prior to 2017 December 8, PX-S860 firmware versions released prior to 2017 December 7) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the web interface of the affected product.

公開: 2019-01-09 最終更新: 2024-11-21 Assigner: [email protected] ソース: [email protected]

総合評価: CVE-2018-0688 は中リスク(43.4/100)。CVSS 深刻度は中。悪用される可能性が高い(EPSS 0.31%、54 パーセンタイル) 推奨対応: 影響資産を整理し、修補計画に組み込んでください。

リスクは変動します。再評価に基づき、本ページの表示内容を更新しています。

CVE-2018-0688 の EPSS(Exploit Prediction Scoring System)スコア

EPSS は日次で悪用されやすさの相対度合いを推定します。パーセンタイルは採点済み CVE の中での相対位置(高いほど相対的に深刻)を示します。

# 日付 旧 EPSS スコア 新 EPSS スコア Δ(新 − 旧)
1 2026-04-11 0.19% 0.31% +0.12%
2 2025-03-17 0.12% 0.19% +0.07%
3 2023-03-07 0.12%

EPSS の全履歴 (全 5 件)

CVE-2018-0688 の CVSS(Common Vulnerability Scoring System)指標

この CVE の CVSS 指標。

ベーススコア バージョン 深刻度 ベクトル 悪用しやすさ 影響 スコアの出典
6.1 3.0 MEDIUM
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N クリックして展開
攻撃ベクター (AV:N)
インターネットなど、ルーティングされたネットワーク越しに遠隔から悪用しうる。端末の前にいる必要はない。
攻撃の複雑さ (AC:L)
攻撃者が条件を満たせば、レース条件や珍しい構成に依存せずに再現しやすい。
必要な権限 (PR:N)
事前のログインや昇格は不要で、匿名アクセスのまま踏み台にしうる。
ユーザーの関与 (UI:R)
インストールの許可、設定変更、悪意あるファイルの実行など、人の一度の判断がトリガーになる。
スコープ (S:C)
脆弱箇所を足がかりに、別コンポーネントや別権限域まで影響が広がりうる。
機密性への影響 (C:L)
一部のデータや属性が漏えいしうるが、全件一括流出といった規模には至らない。
完全性への影響 (I:L)
レコードの一部書き換えや設定の歪みなど、限定的だが検知・復旧が必要な水準。
可用性への影響 (A:N)
業務継続に支障が出るレベルの停止や劣化は想定されない。
2.8 2.7 [email protected]
5.8 2.0 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N クリックして展開
アクセス経路 (AV:N)
ルーティング可能なネットワーク越しに、遠隔から到達・悪用しうる。
アクセスの複雑さ (AC:M)
多少の有利条件は要るが、極端なレアケースではない。
認証 (AU:N)
認証を経ずに攻撃を完結できる。
機密性への影響 (C:P)
機密性は部分的に損なわれる。
完全性への影響 (I:P)
完全性は部分的に損なわれる。
可用性への影響 (A:N)
可用性は損なわれない。
8.6 4.9 [email protected]

CVE-2018-0688 の弱点分類(列挙)

CVE-2018-0688 の影響を受けるソフトウェア/構成

ベンダー 製品 バージョン 生の CPE
epson ds-570w_firmware < 2018-03-13 cpe:2.3:o:epson:ds-570w_firmware:*:*:*:*:*:*:*:*
epson ds-780n_firmware < 2018-03-13 cpe:2.3:o:epson:ds-780n_firmware:*:*:*:*:*:*:*:*
epson ep-10va_firmware < 2017-09-04 cpe:2.3:o:epson:ep-10va_firmware:*:*:*:*:*:*:*:*
epson ep-30va_firmware < 2017-06-19 cpe:2.3:o:epson:ep-30va_firmware:*:*:*:*:*:*:*:*
epson ep-707a_firmware < 2017-08-01 cpe:2.3:o:epson:ep-707a_firmware:*:*:*:*:*:*:*:*
epson ep-708a_firmware < 2017-08-07 cpe:2.3:o:epson:ep-708a_firmware:*:*:*:*:*:*:*:*
epson ep-709a_firmware < 2017-06-12 cpe:2.3:o:epson:ep-709a_firmware:*:*:*:*:*:*:*:*
epson ep-777a_firmware < 2017-08-01 cpe:2.3:o:epson:ep-777a_firmware:*:*:*:*:*:*:*:*
epson ep-807ab_firmware < 2017-08-01 cpe:2.3:o:epson:ep-807ab_firmware:*:*:*:*:*:*:*:*
epson ep-807aw_firmware < 2017-08-01 cpe:2.3:o:epson:ep-807aw_firmware:*:*:*:*:*:*:*:*
epson ep-807ar_firmware < 2017-08-01 cpe:2.3:o:epson:ep-807ar_firmware:*:*:*:*:*:*:*:*
epson ep-808ab_firmware < 2017-08-07 cpe:2.3:o:epson:ep-808ab_firmware:*:*:*:*:*:*:*:*
epson ep-808aw_firmware < 2017-08-07 cpe:2.3:o:epson:ep-808aw_firmware:*:*:*:*:*:*:*:*
epson ep-808ar_firmware < 2017-08-07 cpe:2.3:o:epson:ep-808ar_firmware:*:*:*:*:*:*:*:*
epson ep-879ab_firmware < 2017-06-12 cpe:2.3:o:epson:ep-879ab_firmware:*:*:*:*:*:*:*:*
epson ep-879aw_firmware < 2017-06-12 cpe:2.3:o:epson:ep-879aw_firmware:*:*:*:*:*:*:*:*
epson ep-879ar_firmware < 2017-06-12 cpe:2.3:o:epson:ep-879ar_firmware:*:*:*:*:*:*:*:*
epson ep-907f_firmware < 2017-08-01 cpe:2.3:o:epson:ep-907f_firmware:*:*:*:*:*:*:*:*
epson ep-977a3_firmware < 2017-08-01 cpe:2.3:o:epson:ep-977a3_firmware:*:*:*:*:*:*:*:*
epson ep-978a3_firmware < 2017-08-07 cpe:2.3:o:epson:ep-978a3_firmware:*:*:*:*:*:*:*:*
epson ep-979a3_firmware < 2017-06-12 cpe:2.3:o:epson:ep-979a3_firmware:*:*:*:*:*:*:*:*
epson ep-m570t_firmware < 2017-09-06 cpe:2.3:o:epson:ep-m570t_firmware:*:*:*:*:*:*:*:*
epson ew-m5071ft_firmware < 2017-11-02 cpe:2.3:o:epson:ew-m5071ft_firmware:*:*:*:*:*:*:*:*
epson ew-m660ft_firmware < 2018-04-19 cpe:2.3:o:epson:ew-m660ft_firmware:*:*:*:*:*:*:*:*
epson ew-m770t_firmware < 2017-09-06 cpe:2.3:o:epson:ew-m770t_firmware:*:*:*:*:*:*:*:*
epson pf-70_firmware < 2018-04-20 cpe:2.3:o:epson:pf-70_firmware:*:*:*:*:*:*:*:*
epson pf-71_firmware < 2017-07-18 cpe:2.3:o:epson:pf-71_firmware:*:*:*:*:*:*:*:*
epson pf-81_firmware < 2017-09-14 cpe:2.3:o:epson:pf-81_firmware:*:*:*:*:*:*:*:*
epson px-048a_firmware < 2017-07-04 cpe:2.3:o:epson:px-048a_firmware:*:*:*:*:*:*:*:*
epson px-049a_firmware < 2017-09-11 cpe:2.3:o:epson:px-049a_firmware:*:*:*:*:*:*:*:*
epson px-437a_firmware < 2017-07-24 cpe:2.3:o:epson:px-437a_firmware:*:*:*:*:*:*:*:*
epson px-m350f_firmware < 2018-02-23 cpe:2.3:o:epson:px-m350f_firmware:*:*:*:*:*:*:*:*
epson px-m5040f_firmware < 2017-11-20 cpe:2.3:o:epson:px-m5040f_firmware:*:*:*:*:*:*:*:*
epson px-m5041f_firmware < 2017-11-20 cpe:2.3:o:epson:px-m5041f_firmware:*:*:*:*:*:*:*:*
epson px-m650a_firmware < 2017-10-17 cpe:2.3:o:epson:px-m650a_firmware:*:*:*:*:*:*:*:*
epson px-m650f_firmware < 2017-10-17 cpe:2.3:o:epson:px-m650f_firmware:*:*:*:*:*:*:*:*
epson px-m680f_firmware < 2017-06-29 cpe:2.3:o:epson:px-m680f_firmware:*:*:*:*:*:*:*:*
epson px-m7050f_firmware < 2017-10-13 cpe:2.3:o:epson:px-m7050f_firmware:*:*:*:*:*:*:*:*
epson px-m7050fp_firmware < 2017-10-13 cpe:2.3:o:epson:px-m7050fp_firmware:*:*:*:*:*:*:*:*
epson px-m7050fx_firmware < 2017-11-07 cpe:2.3:o:epson:px-m7050fx_firmware:*:*:*:*:*:*:*:*
epson px-m7070fx_firmware < 2017-04-27 cpe:2.3:o:epson:px-m7070fx_firmware:*:*:*:*:*:*:*:*
epson px-m740f_firmware < 2017-06-29 cpe:2.3:o:epson:px-m740f_firmware:*:*:*:*:*:*:*:*
epson px-m781f_firmware < 2017-06-27 cpe:2.3:o:epson:px-m781f_firmware:*:*:*:*:*:*:*:*
epson px-m840f_firmware < 2017-11-16 cpe:2.3:o:epson:px-m840f_firmware:*:*:*:*:*:*:*:*
epson px-m840fx_firmware < 2017-12-08 cpe:2.3:o:epson:px-m840fx_firmware:*:*:*:*:*:*:*:*
epson px-m860f_firmware < 2017-10-25 cpe:2.3:o:epson:px-m860f_firmware:*:*:*:*:*:*:*:*
epson px-s05b_firmware < 2018-03-09 cpe:2.3:o:epson:px-s05b_firmware:*:*:*:*:*:*:*:*
epson px-s05w_firmware < 2018-03-09 cpe:2.3:o:epson:px-s05w_firmware:*:*:*:*:*:*:*:*
epson px-s350_firmware < 2018-02-23 cpe:2.3:o:epson:px-s350_firmware:*:*:*:*:*:*:*:*
epson px-s5040_firmware < 2017-11-20 cpe:2.3:o:epson:px-s5040_firmware:*:*:*:*:*:*:*:*
epson px-s7050_firmware < 2018-02-21 cpe:2.3:o:epson:px-s7050_firmware:*:*:*:*:*:*:*:*
epson px-s7050ps_firmware < 2018-02-21 cpe:2.3:o:epson:px-s7050ps_firmware:*:*:*:*:*:*:*:*
epson px-s7050x_firmware < 2017-11-07 cpe:2.3:o:epson:px-s7050x_firmware:*:*:*:*:*:*:*:*
epson px-s7070x_firmware < 2017-04-27 cpe:2.3:o:epson:px-s7070x_firmware:*:*:*:*:*:*:*:*
epson px-s740_firmware < 2017-12-03 cpe:2.3:o:epson:px-s740_firmware:*:*:*:*:*:*:*:*
epson px-s840_firmware < 2017-11-16 cpe:2.3:o:epson:px-s840_firmware:*:*:*:*:*:*:*:*
epson px-s840x_firmware < 2017-12-08 cpe:2.3:o:epson:px-s840x_firmware:*:*:*:*:*:*:*:*
epson px-s860_firmware < 2017-12-07 cpe:2.3:o:epson:px-s860_firmware:*:*:*:*:*:*:*:*

CVE-2018-0688 の参考情報

cvelogic Threat Intelligence