CVE-2023-39341
Last modified
CVE-2023-39341 is a low-severity vulnerability rated 3.3/10 on the CVSS scale. "FFRI yarai", "FFRI yarai Home and Business Edition" and their OEM products handle exceptional conditions improperly, which may lead to denial-of-service (DoS) condition. Affected products and versions are as follows: FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0, FFRI yarai Home and Business Edition version 1.4.0, InfoTrace Mark II Malware Protection (Mark II Zerona) versions 3.0.1 to 3.2.2, Zerona / Zerona PLUS versions 3.2.32 to 3.2.36, ActSecure χ versions 3.4.0 to 3.4.6 and 3.5.0, Dual Safe Powered by FFRI yarai version 1.4.1, EDR Plus Pack (Bundled FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0), and EDR Plus Pack Cloud (Bundled FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0).. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
"FFRI yarai", "FFRI yarai Home and Business Edition" and their OEM products handle exceptional conditions improperly, which may lead to denial-of-service (DoS) condition. Affected products and versions are as follows: FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0, FFRI yarai Home and Business Edition version 1.4.0, InfoTrace Mark II Malware Protection (Mark II Zerona) versions 3.0.1 to 3.2.2, Zerona / Zerona PLUS versions 3.2.32 to 3.2.36, ActSecure χ versions 3.4.0 to 3.4.6 and 3.5.0, Dual Safe Powered by FFRI yarai version 1.4.1, EDR Plus Pack (Bundled FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0), and EDR Plus Pack Cloud (Bundled FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0).
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ffri | Dual Safe | 1.4.1 |
| Ffri | Ffri Yarai | >= 3.4.0, <= 3.4.6 |
| Ffri | Ffri Yarai | 1.4.0 |
| Ffri | Ffri Yarai | 3.5.0 |
| Soliton | Infotrace Mark Ii Malware Protection | >= 3.0.1, <= 3.2.2 |
| Soliton | Zerona | >= 3.2.32, <= 3.2.36 |
| Soliton | Zerona Plus | >= 3.2.32, <= 3.2.36 |
| Nec | Actsecure X Managed Security Service | >= 3.4.0, <= 3.4.6 |
| Nec | Actsecure X Managed Security Service | 3.5.0 |
| Skygroup | Edr Plus Pack | >= 3.4.0, <= 3.4.6 |
| Skygroup | Edr Plus Pack | 3.5.0 |
| Skygroup | Edr Plus Pack Cloud | >= 3.4.0, <= 3.4.6 |
| Skygroup | Edr Plus Pack Cloud | 3.5.0 |
References
- https://jvn.jp/en/jp/JVN42527152/Third Party Advisory
- https://www.ffri.jp/security-info/index.htmVendor Advisory
- https://www.skyseaclientview.net/news/230807_01/Third Party Advisory
- https://www.soliton.co.jp/support/zerona_notice_2023.htmlThird Party Advisory
- https://www.sourcenext.com/support/i/2023/230718_01Third Party Advisory
- https://www.support.nec.co.jp/View.aspx?id=3140109240Permissions Required
- https://jvn.jp/en/jp/JVN42527152/Third Party Advisory
- https://www.ffri.jp/security-info/index.htmVendor Advisory
- https://www.skyseaclientview.net/news/230807_01/Third Party Advisory
- https://www.soliton.co.jp/support/zerona_notice_2023.htmlThird Party Advisory
- https://www.sourcenext.com/support/i/2023/230718_01Third Party Advisory
- https://www.support.nec.co.jp/View.aspx?id=3140109240Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-39341?
How severe is CVE-2023-39341?
How do I fix CVE-2023-39341?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-39336An unspecified SQL Injection vulnerability in Ivanti Endpoin…8.8
- CVE-2023-39337A security vulnerability in EPMM Versions 11.10, 11.9 and 11…9.1
- CVE-2023-39338Enables an authenticated user (enrolled device) to access a …6.8
- CVE-2023-39339A vulnerability exists on all versions of Ivanti Policy Secu…4.9
- CVE-2023-3934Rejected reason: Please discard this CVE, we are not using t…
- CVE-2023-39340A vulnerability exists on all versions of Ivanti Connect Sec…7.5
- CVE-2023-39342Dangerzone is software for converting potentially dangerous …3.6
- CVE-2023-39343Sulu is an open-source PHP content management system based o…4.3
- CVE-2023-39344social-media-skeleton is an uncompleted social media project…8.8
- CVE-2023-39345strapi is an open-source headless CMS. Versions prior to 4.1…7.5
- CVE-2023-39346LinuxASMCallGraph is software for drawing the call graph of …9.8
- CVE-2023-39347Cilium is a networking, observability, and security solution…9
Are you affected by CVE-2023-39341?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
