CVE-2025-64310
CRITICAL
9.8
CVSS 3.1
Description
EPSON WebConfig and Epson Web Control for SEIKO EPSON Projector Products do not restrict excessive authentication attempts. An administrative user's password may be identified through a brute force attack.
Metadata
Severity & Metrics
9.8
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (2)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| SEIKO EPSON CORPORATION | Epson Web Control for SEIKO EPSON Projector Products | — | see the information provided by the vendor |
| SEIKO EPSON CORPORATION | EPSON WebConfig for SEIKO EPSON Projector Products | — | see the information provided by the vendor |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-307 | cna | Improper restriction of excessive authentication attempts |
CVSS scores (2)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 9.8 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 9.3 | CRITICAL | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
References (3)