CVE-2020-28929 describes an unrestricted access vulnerability in EPSON EPS TSE Server 8 (version 21.0.11) that allows unauthenticated attackers to remotely download administrative hashed credentials. This critical vulnerability (CVSS 9.8) has a low attack complexity and no user interaction required, enabling full confidentiality, integrity, and availability impact. While there is no known active exploitation, public exploit code, or significant community discussion, the high CVSS score and FAUCET Risk Score of 81/100 indicate its severe potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
21.0.11CPE matchmatch criteria | cpe:2.3:o:epson:eps_tse_server_8_firmware:21.0.11:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.