CVE-2023-38555
Last modified
CVE-2023-38555 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Authentication bypass vulnerability in Fujitsu network devices Si-R series and SR-M series allows a network-adjacent unauthenticated attacker to obtain, change, and/or reset configuration settings of the affected products. Affected products and versions are as follows: Si-R 30B all versions, Si-R 130B all versions, Si-R 90brin all versions, Si-R570B all versions, Si-R370B all versions, Si-R220D all versions, Si-R G100 V02.54 and earlier, Si-R G200 V02.54 and earlier, Si-R G100B V04.12 and earlier, Si-R G110B V04.12 and earlier, Si-R G200B V04.12 and earlier, Si-R G210 V20.52 and earlier, Si-R G211 V20.52 and earlier, Si-R G120 V20.52 and earlier, Si-R G121 V20.52 and earlier, and SR-M 50AP1 all versions.. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
Authentication bypass vulnerability in Fujitsu network devices Si-R series and SR-M series allows a network-adjacent unauthenticated attacker to obtain, change, and/or reset configuration settings of the affected products. Affected products and versions are as follows: Si-R 30B all versions, Si-R 130B all versions, Si-R 90brin all versions, Si-R570B all versions, Si-R370B all versions, Si-R220D all versions, Si-R G100 V02.54 and earlier, Si-R G200 V02.54 and earlier, Si-R G100B V04.12 and earlier, Si-R G110B V04.12 and earlier, Si-R G200B V04.12 and earlier, Si-R G210 V20.52 and earlier, Si-R G211 V20.52 and earlier, Si-R G120 V20.52 and earlier, Si-R G121 V20.52 and earlier, and SR-M 50AP1 all versions.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fujitsu | Si-R 30b Firmware | All versions |
| Fujitsu | Si-R 130b Firmware | All versions |
| Fujitsu | Si-R 90brin Firmware | All versions |
| Fujitsu | Si-R570b Firmware | All versions |
| Fujitsu | Si-R370b Firmware | All versions |
| Fujitsu | Si-R220d Firmware | All versions |
| Fujitsu | Si-R G100 Firmware | <= 02.54 |
| Fujitsu | Si-R G200 Firmware | <= 02.54 |
| Fujitsu | Si-R G100b Firmware | <= 04.12 |
| Fujitsu | Si-R G110b Firmware | <= 04.12 |
| Fujitsu | Si-R G200b Firmware | <= 04.12 |
| Fujitsu | Si-R G210 Firmware | <= 20.52 |
| Fujitsu | Si-R G211 Firmware | <= 20.52 |
| Fujitsu | Si-R G120 Firmware | <= 20.52 |
| Fujitsu | Si-R G121 Firmware | <= 20.52 |
| Fujitsu | Sr-M 50ap1 Firmware | All versions |
References
- https://jvn.jp/en/vu/JVNVU96643580/Third Party Advisory
- https://jvn.jp/en/vu/JVNVU96643580/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-38555?
How severe is CVE-2023-38555?
How do I fix CVE-2023-38555?
Are you affected by CVE-2023-38555?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
