Epson Sicherheitshinweise und Benachrichtigungen
- Sicherheitsleitfaden
- Sicherheitsbenachrichtigungen
- Richtlinie zur Offenlegung von Sicherheitslücken
- Eine Sicherheitslücke melden
- Funkgeräterichtlinie (RED)
Epson Sicherheitsmanifest
Um die Sicherheit aller Kunden zu gewährleisten, verwendet Epson einheitliche Sicherheitsrahmenwerke und konsistente Methoden bei der Entwicklung und Lieferung aller Produkte, von Geräten für den Büro- und Heimbereich bis hin zu kommerziellen/industriellen Belegdruckern und Großformatdruckern (LFPs).
Sicherheitsleitfaden für Unternehmensprodukte
Stärken Sie die funktionalen Netzwerkfähigkeiten von Unternehmensdruckern und MFPs, um die Benutzerfreundlichkeit mit einer Auswahl an Sicherheitsfunktionen für Computer und Server bei der Verbindung mit und Nutzung eines Netzwerks zu verbessern.
Sicherheitsleitfaden für Produkte
Sicherheitsleitfaden:
Kunden, die eine Heimnetzwerkumgebung verwenden
Sicherheitsleitfaden:
Kunden, die eine Unternehmens-Intranetumgebung nutzen
Sicherheitsleitfaden:
Kunden, die POS-Produkte verwenden. Wählen Sie diese Option unabhängig von Ihrer Netzwerkumgebung.
Sicherheitsleitfaden:
Drucker für Privatanwender und Unternehmen
Sicherheitsleitfaden:
Projektoren
Sicherheitsleitfaden:
Projektoren (Anhang)
Sicherheitsleitfaden:
Großformatdrucker
Sicherheitsleitfaden:
Scanner
Sicherheitsleitfaden:
POS-Drucker
Sicherheitsleitfaden:
Etikettendrucker
Liste der Funktionen und unterstützte Modelle
Geschäftlicher Tintenstrahldrucker Funktion
Liste und unterstützte Modelle:
Großformat-und kommerzielle Drucker Funktion
Liste und unterstützte Modelle:
Funktion des Scanners
Liste und unterstützte Modelle:
Projektorfunktion
Liste der unterstützten Modelle:
Sicherheits-Whitepaper und Informationen zu Lösungen
Sicherheits-Whitepaper für
Epson Print Admin:
Sicherheits-Whitepaper für
Epson Device Admin:
Sicherheits-Whitepaper für
Document Capture Pro Server:
Sicherheits-Whitepaper für
Epson Remote Services:
Please select a security notification below for details:
| Security Notification | Product | ID | Release Date |
|---|---|---|---|
| Vulnerability in Web Config for Printers and Scanners | -- | CVE-2026-58315 | 07/07/2026 |
| Command Execution Vulnerability in Epson POS Printers Connected to a Network | All products implementing ESC/POS | CVE-2026-23767 | 05/03/2026 |
| Vulnerability that allows arbitrary command execution in the printer's Web Config | -- | CVE-2025-66635 | 16/12/2025 |
| Vulnerability in EPSON WebConfig / Epson Web Control for Projector Products | -- | CVE-2025-64310 | 20/11/2025 |
| Local privilege escalation in Windows OS through installed EPSON printers installed in non-English language | -- | CVE-2025-42598 | 18/04/2025 |
| Insecure Initial Password Configuration in Epson WebConfig Vulnerability | -- | CVE-2024-47295 | 01/10/2024 |
| Cross-Site Scripting (XSS) Vulnerability | -- | CVE-2023-23572 | 18/09/2023 |
| Vulnerability in Web Config in Printer Products | -- | Click Here | 03/08/2023 |
| Vulnerability in Web Config in Printers and Network Interface Products | -- | CVE-2023-27520 | 09/06/2023 |
| Security Measures for Epson Network Products | -- | Click Here | 26/11/2020 |
Epson Vulnerability Disclosure Policy
Seiko Epson Corporation and its sales companies ("we", "us", "our") are eager to collect information on security vulnerabilities in our "Epson Brand" products and services (the "Products"), investigate their impact and disclose information as necessary to ensure that our customers can use our Products with confidence.
In addition, based on the principles of Coordinated Vulnerability Disclosure (CVD), we will work in cooperation with reporters and relevant stakeholders in handling vulnerabilities, and we will not take legal action against reporters who act in good faith in accordance with this policy.
In this respect, is the aim of this coordinated vulnerability disclosure policy to detail a structured process through which vulnerabilities can be reported by any individual or entity (also referred herein as a “reporter") to us in a manner allowing us to diagnose and remedy such vulnerabilities before detailed vulnerability information is disclosed to third parties or to the public.
1. Application
This policy applies to all vulnerabilities (*1) reported to us. Reporters are requested to read and comply with this policy carefully before reporting vulnerabilities.
*1: Vulnerability is a weakness, susceptibility or flaw in an Epson-branded product with digital elements that can be exploited by a cyber threat, potentially affecting the confidentiality, integrity, authenticity or availability of data, systems, or function".
2. How to report vulnerabilities
If you wish to report a vulnerability (undisclosed vulnerability) for one of our products, please submit a report via the link below.
3. The process after a vulnerability report
3.1 Acknowledgement of receipt
The reporter submitting the report will receive an acknowledgement of receipt from us within five working days, starting from the day after the day on which the report is sent.
3.2 Identification of vulnerabilities
The received vulnerabilities are checked by our technical team and the results are fed back to the reporter. If there are any unclear points in the reported vulnerability information, we will contact you using your specified method of communication.
In some cases, we may decide that the vulnerability is "not covered by the vulnerability response". For example, in the following cases.
- Known vulnerabilities.
- Product support is no longer available.
3.3 Addressing vulnerabilities
If we determine that there is a vulnerability in our product , we will provide a remedy with a fixed module that addresses the vulnerability or provide a workaround as quickly as possible. Please note that when we provide a fixed module, we may ask the reporter to confirm that the vulnerability has been properly addressed.
3.4 Vulnerability disclosure.
If it is deemed necessary to inform third parties or the public, the security advisory will be posted on the following website once appropriate mitigation measures are available to reduce potential risk, so that customers can implement appropriate measures.
In addition, if the reporter makes the disclosure, the reporter is requested to coordinate the content of the disclosure (e.g. not including information that may give the attacker an advantage) and the schedule of the disclosure.
4. About Rewards
We sincerely appreciate those who take the time and effort to report vulnerabilities in accordance with this policy, but we do not offer any compensation for reporting vulnerabilities.
5. Code of Conduct
- With regard to the disclosure of vulnerabilities: We kindly request that the reporter shall not disclose vulnerability-related information to third parties without a valid reason.
However, if you need to disclose vulnerability-related information for legitimate reasons, please consult us in advance. - With regard to when vulnerabilities are discovered and verified: Please do not do the following in order to search for and verify vulnerabilities:
- Violating applicable laws and regulations
- Accessing unnecessary, excessive or voluminous data
- Altering data on our systems or services
- Using high-intensity invasive or destructive scanning tools to discover vulnerabilities
- Attempting or reporting any form of denial of service, such as overwhelming our services with a high volume of requests
- Interfering with our services or systems
Ab dem 1. August 2025 müssen alle drahtlosen Geräte, die auf den Märkten der EU, des Vereinigten Königreichs und der EFTA angeboten werden, der aktualisierten Funkgeräterichtlinie (Radio Equipment Directive, RED) entsprechen. „Auf dem Markt angeboten” bezieht sich auf den Zeitpunkt, zu dem ein Gerät in die Region gelangt ist und die Zollabfertigung abgeschlossen wurde.
Was ist das Ziel?
So stellen Sie sicher, dass bei den Geräten folgendes gewährleistet ist:
- Sicher in der Anwendung
- Schutz vor Cyber-Bedrohungen
- Kompatibel mit anderen Technologien
- Effizienter Einsatz von Funkfrequenzen
Was ist abgedeckt?
Elektronische Geräte im Sinne der Richtlinie sind solche, die entweder selbst Radiowellen absichtlich senden und empfangen oder Zubehör enthalten, das diese Funktion zur Kommunikation ermöglicht. Im Allgemeinen fällt ein Gerät, das aktiv den Datenaustausch mit dem Internet initiiert, in den Anwendungsbereich von RED.
Beispiele sind unter anderem:
- Drucker mit Wi-Fi-Funktionalität, Projektoren und Scanner
- Telefone
- Wi-Fi/Bluetooth-Geräte
- GPS
- Radios
Warum es wichtig ist:
Hersteller müssen Daten verschlüsseln, die Privatsphäre der Benutzer schützen und strenge Sicherheitsstandards erfüllen.
Weitere Informationen:
Erfahren Sie, wie sich RED auf Ihr Epson Gerät auswirkt, indem Sie auf die Schaltfläche „Mehr erfahren” klicken.
RED-Richtlinie — Häufig gestellte Fragen
Allgemein
Was ist die RED-Richtlinie?
Welche Änderungen treten im August 2025 in Kraft?
Was ist erforderlich, um konform zu sein?
Welche Art von Geräten sind betroffen?
Woher weiß ich, ob mein Gerät betroffen ist?
Wer ist dafür verantwortlich, die Konformität sicherzustellen?
Sind Epson Geräte konform?
Was muss ich tun, wenn ich mein Gerät vor August 2025 erworben habe?
Was muss ich tun, wenn ich nach August 2025 ein Gerät kaufe?
Woher weiß ich, welche Firmware-Version ich benötige und wo kann ich sie herunterladen?
Probleme mit neuen Druckern
Warum funktioniert mein neuer Drucker nicht?
Warum funktioniert mein Drucker nach einem Firmware-Update nicht?
Warum funktioniert mein Scanner nicht?