Lucene search

K
cve[email protected]CVE-2023-38555
HistoryJul 26, 2023 - 8:15 a.m.

CVE-2023-38555

2023-07-2608:15:10
CWE-287
web.nvd.nist.gov
12
cve-2023-38555
fujitsu
network devices
si-r series
sr-m series
authentication bypass
vulnerability
nvd
configuration settings

8.8 High

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

8.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

23.1%

Authentication bypass vulnerability in Fujitsu network devices Si-R series and SR-M series allows a network-adjacent unauthenticated attacker to obtain, change, and/or reset configuration settings of the affected products. Affected products and versions are as follows: Si-R 30B all versions, Si-R 130B all versions, Si-R 90brin all versions, Si-R570B all versions, Si-R370B all versions, Si-R220D all versions, Si-R G100 V02.54 and earlier, Si-R G200 V02.54 and earlier, Si-R G100B V04.12 and earlier, Si-R G110B V04.12 and earlier, Si-R G200B V04.12 and earlier, Si-R G210 V20.52 and earlier, Si-R G211 V20.52 and earlier, Si-R G120 V20.52 and earlier, Si-R G121 V20.52 and earlier, and SR-M 50AP1 all versions.

Affected configurations

Vulners
NVD
Node
fujitsu_limitedsi-r_g100Match02.54
OR
fujitsu_limitedsi-r_g200Match02.54
OR
fujitsu_limitedsi-r_g100bMatch04.12
OR
fujitsu_limitedsi-r_g110bMatch04.12
OR
fujitsu_limitedsi-r_g200bMatch04.12
OR
fujitsu_limitedsi-r_g210Match20.52
OR
fujitsu_limitedsi-r_g211Match20.52
OR
fujitsu_limitedsi-r_g120Match20.52
OR
fujitsu_limitedsi-r_g121Match20.52

CNA Affected

[
  {
    "vendor": "Fujitsu Limited",
    "product": "Si-R 30B",
    "versions": [
      {
        "version": "All versions ",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Fujitsu Limited",
    "product": "Si-R 130B",
    "versions": [
      {
        "version": "All versions ",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Fujitsu Limited",
    "product": "Si-R 90brin",
    "versions": [
      {
        "version": "All versions ",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Fujitsu Limited",
    "product": "Si-R570B",
    "versions": [
      {
        "version": "All versions ",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Fujitsu Limited",
    "product": "Si-R370B",
    "versions": [
      {
        "version": "All versions ",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Fujitsu Limited",
    "product": "Si-R220D",
    "versions": [
      {
        "version": "All versions ",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Fujitsu Limited",
    "product": "Si-R G100",
    "versions": [
      {
        "version": "V02.54 and earlier ",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Fujitsu Limited",
    "product": "Si-R G200",
    "versions": [
      {
        "version": "V02.54 and earlier ",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Fujitsu Limited",
    "product": "Si-R G100B",
    "versions": [
      {
        "version": "V04.12 and earlier ",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Fujitsu Limited",
    "product": "Si-R G110B",
    "versions": [
      {
        "version": "V04.12 and earlier ",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Fujitsu Limited",
    "product": "Si-R G200B",
    "versions": [
      {
        "version": "V04.12 and earlier ",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Fujitsu Limited",
    "product": "Si-R G210",
    "versions": [
      {
        "version": "V20.52 and earlier ",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Fujitsu Limited",
    "product": "Si-R G211",
    "versions": [
      {
        "version": "V20.52 and earlier ",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Fujitsu Limited",
    "product": "Si-R G120",
    "versions": [
      {
        "version": "V20.52 and earlier ",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Fujitsu Limited",
    "product": "Si-R G121",
    "versions": [
      {
        "version": "V20.52 and earlier ",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Fujitsu Limited",
    "product": "SR-M 50AP1",
    "versions": [
      {
        "version": "All versions",
        "status": "affected"
      }
    ]
  }
]

8.8 High

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

8.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

23.1%

Related for CVE-2023-38555