#VU28174 Authentication bypass using an alternate path or channel in Epson EB-1470Ui - CVE-2020-6091
Published: May 22, 2020
Epson EB-1470Ui
Seiko Epson Corporation
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exist due to improper implementation of the authentication process in the ESPON Web Control functionality of Epson EB-1470Ui MAIN: 98009273ESWWV107 MAIN2: 8X7325WWV303. A remote attacker can send a specially crafted HTTP request, bypass authentication and gain full read/write configuration access on the target device.