Lucene search

K
nvd[email protected]NVD:CVE-2023-38555
HistoryJul 26, 2023 - 8:15 a.m.

CVE-2023-38555

2023-07-2608:15:10
CWE-287
web.nvd.nist.gov
vulnerability
fujitsu
network devices
authentication bypass
unauthenticated attacker
configuration settings
si-r series
sr-m series
affected products
versions

8.8 High

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

8.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

23.1%

Authentication bypass vulnerability in Fujitsu network devices Si-R series and SR-M series allows a network-adjacent unauthenticated attacker to obtain, change, and/or reset configuration settings of the affected products. Affected products and versions are as follows: Si-R 30B all versions, Si-R 130B all versions, Si-R 90brin all versions, Si-R570B all versions, Si-R370B all versions, Si-R220D all versions, Si-R G100 V02.54 and earlier, Si-R G200 V02.54 and earlier, Si-R G100B V04.12 and earlier, Si-R G110B V04.12 and earlier, Si-R G200B V04.12 and earlier, Si-R G210 V20.52 and earlier, Si-R G211 V20.52 and earlier, Si-R G120 V20.52 and earlier, Si-R G121 V20.52 and earlier, and SR-M 50AP1 all versions.

Affected configurations

NVD
Node
fujitsusi-r_30b_firmware
AND
fujitsusi-r_30bMatch-
Node
fujitsusi-r_130b_firmware
AND
fujitsusi-r_130bMatch-
Node
fujitsusi-r_90brin_firmware
AND
fujitsusi-r_90brinMatch-
Node
fujitsusi-r570b_firmware
AND
fujitsusi-r570bMatch-
Node
fujitsusi-r370b_firmware
AND
fujitsusi-r370bMatch-
Node
fujitsusi-r220d_firmware
AND
fujitsusi-r220dMatch-
Node
fujitsusi-r_g100_firmwareRange02.54
AND
fujitsusi-r_g100Match-
Node
fujitsusi-r_g200_firmwareRange02.54
AND
fujitsusi-r_g200Match-
Node
fujitsusi-r_g100b_firmwareRange04.12
AND
fujitsusi-r_g100bMatch-
Node
fujitsusi-r_g110b_firmwareRange04.12
AND
fujitsusi-r_g110bMatch-
Node
fujitsusi-r_g200b_firmwareRange04.12
AND
fujitsusi-r_g200bMatch-
Node
fujitsusi-r_g210_firmwareRange20.52
AND
fujitsusi-r_g210Match-
Node
fujitsusi-r_g211_firmwareRange20.52
AND
fujitsusi-r_g211Match-
Node
fujitsusi-r_g120_firmwareRange20.52
AND
fujitsusi-r_g120Match-
Node
fujitsusi-r_g121_firmwareRange20.52
AND
fujitsusi-r_g121Match-
Node
fujitsusr-m_50ap1_firmware
AND
fujitsusr-m_50ap1Match-

8.8 High

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

8.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

23.1%

Related for NVD:CVE-2023-38555