Lucene search

K
cve[email protected]CVE-2023-39341
HistoryAug 09, 2023 - 3:15 a.m.

CVE-2023-39341

2023-08-0903:15:43
CWE-755
web.nvd.nist.gov
23
cve-2023-39341
ffri yarai
dos vulnerability
exception handling
infotrace mark ii malware protection
zerona
actsecure
edr plus pack

3.3 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

4.2 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.3%

“FFRI yarai”, “FFRI yarai Home and Business Edition” and their OEM products handle exceptional conditions improperly, which may lead to denial-of-service (DoS) condition.
Affected products and versions are as follows: FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0, FFRI yarai Home and Business Edition version 1.4.0, InfoTrace Mark II Malware Protection (Mark II Zerona) versions 3.0.1 to 3.2.2, Zerona / Zerona PLUS versions 3.2.32 to 3.2.36, ActSecure χ versions 3.4.0 to 3.4.6 and 3.5.0, Dual Safe Powered by FFRI yarai version 1.4.1, EDR Plus Pack (Bundled FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0), and EDR Plus Pack Cloud (Bundled FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0).

Affected configurations

Vulners
NVD
Node
ffri_security\,_inc.ffri_yaraiRange3.4.03.4.6
OR
ffri_security\,_inc.ffri_yaraiMatch3.5.0
OR
ffri_security\,_inc.ffri_yarai_home_and_business_editionMatch1.4.0
OR
soliton_systems_k.k.infotrace_mark_ii_malware_protection_\(mark_ii_zerona\)Range3.0.13.2.2
OR
soliton_systems_k.k.zerona_\/_zerona_plusRange3.2.323.2.36
OR
necactsecure_x_managed_security_serviceRange3.4.03.4.6
OR
necactsecure_x_managed_security_serviceMatch3.5.0
OR
sourcenext_corporationdual_safe_powered_by_ffri_yaraiMatch1.4.1
OR
sky_co.\,_ltd.edr_plus_packRange3.4.03.4.6
OR
sky_co.\,_ltd.edr_plus_packMatch3.5.0
OR
sky_co.\,_ltd.edr_plus_pack_cloudRange3.4.03.4.6
OR
sky_co.\,_ltd.edr_plus_pack_cloudMatch3.5.0
VendorProductVersionCPE
necactsecure_x_managed_security_service*cpe:2.3:a:nec:actsecure_x_managed_security_service:*:*:*:*:*:*:*:*
necactsecure_x_managed_security_service3.5.0cpe:2.3:a:nec:actsecure_x_managed_security_service:3.5.0:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "FFRI Security, Inc. ",
    "product": "FFRI yarai",
    "versions": [
      {
        "version": "versions 3.4.0 to 3.4.6 and 3.5.0",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "FFRI Security, Inc. ",
    "product": "FFRI yarai Home and Business Edition",
    "versions": [
      {
        "version": "version 1.4.0",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Soliton Systems K.K.",
    "product": "InfoTrace Mark II Malware Protection (Mark II Zerona)",
    "versions": [
      {
        "version": "versions 3.0.1 to 3.2.2",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Soliton Systems K.K.",
    "product": "Zerona / Zerona PLUS",
    "versions": [
      {
        "version": " versions 3.2.32 to 3.2.36",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "NEC Corporation",
    "product": "ActSecure χ",
    "versions": [
      {
        "version": "versions 3.4.0 to 3.4.6 and 3.5.0",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "SOURCENEXT CORPORATION ",
    "product": "Dual Safe Powered by FFRI yarai",
    "versions": [
      {
        "version": "version 1.4.1",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Sky Co., Ltd.",
    "product": "EDR Plus Pack",
    "versions": [
      {
        "version": "Bundled FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Sky Co., Ltd.",
    "product": "EDR Plus Pack Cloud",
    "versions": [
      {
        "version": "Bundled FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0",
        "status": "affected"
      }
    ]
  }
]

3.3 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

4.2 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.3%

Related for CVE-2023-39341