Back to Database
Status published
High
CVE-2020-5674
Untrusted search path vulnerability in the installers of multiple SEIKO...
Vulnerability Description
Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-5674
Credits & Attribution
No credits recorded in the NVD database.
References
More from SEIKO EPSON CORPORATION
View All →CVE-2025-66635
Stack-based buffer overflow vulnerability exists in SEIKO EPSON Web Config....
High
8.6
CVE-2025-64310
EPSON WebConfig and Epson Web Control for SEIKO EPSON Projector...
Critical
9.3
CVE-2025-42598
Multiple SEIKO EPSON printer drivers for Windows OS are configured...
High
8.4
CVE-2024-47295
Insecure initial password configuration issue in SEIKO EPSON Web Config...
High
8.1
CVE-2023-38556
Improper input validation vulnerability in SEIKO EPSON printer Web Config...
Unknown
0
Affected Vendor
SEIKO EPSON CORPORATION
View all reports →Affected Software
the installers of multiple SEIKO EPSON products
Vulnerable Versions:
A wide range of versions for the following products are affected -- Epson Web Installer, EPSON printer drivers, EPSON scanner drivers, EPSON Scan ICM Updaters, EPSON Printer Window!3, EPSON Printer Window!2 Firmware update programs, Network configuration utilities, Network print port monitors, Printer monitor SDK, Colorio series, Large-size printer related software, Laser printers, Copy station related software, Dot impact printer related software, Disk duplicator related software, CRYSTARIO related software, SureLab related software, Offirio Synergyware related software, Scanner related software, Digital cameras and Photo viewers related software, Projector related software, and PULSENSE and WristableGPS related software
Timeline
Official Publish:
November 24th, 2020
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.