CVE-2024-39921

HIGHCVSS 7.5/10EPSS 0.43%

Last modified

CVE-2024-39921 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Observable timing discrepancy issue exists in IPCOM EX2 Series V01L02NF0001 to V01L06NF0401, V01L20NF0001 to V01L20NF0401, V02L20NF0001 to V02L21NF0301, and IPCOM VE2 Series V01L04NF0001 to V01L06NF0112. If this vulnerability is exploited, some of the encrypted communication may be decrypted by an attacker who can obtain the contents of the communication.. EPSS estimates a 0.43% chance of exploitation in the next 30 days.

Description

Observable timing discrepancy issue exists in IPCOM EX2 Series V01L02NF0001 to V01L06NF0401, V01L20NF0001 to V01L20NF0401, V02L20NF0001 to V02L21NF0301, and IPCOM VE2 Series V01L04NF0001 to V01L06NF0112. If this vulnerability is exploited, some of the encrypted communication may be decrypted by an attacker who can obtain the contents of the communication.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
0.43%

34.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
FujitsuIpcom Ve2 Ls 100 Firmware>= v01l04nf0001, <= v01l06nf0112
FujitsuIpcom Ve2 Ls 200 Firmware>= v01l04nf0001, <= v01l06nf0112
FujitsuIpcom Ve2 Ls 220 Firmware>= v01l04nf0001, <= v01l06nf0112
FujitsuIpcom Ve2 Ls Plus 100 Firmware>= v01l04nf0001, <= v01l06nf0112
FujitsuIpcom Ve2 Ls Plus 200 Firmware>= v01l04nf0001, <= v01l06nf0112
FujitsuIpcom Ve2 Ls Plus 220 Firmware>= v01l04nf0001, <= v01l06nf0112
FujitsuIpcom Ve2 Ls Plus2 200 Firmware>= v01l04nf0001, <= v01l06nf0112
FujitsuIpcom Ve2 Ls Plus2 220 Firmware>= v01l04nf0001, <= v01l06nf0112
FujitsuIpcom Ve2 Sc Plus 100 Firmware>= v01l04nf0001, <= v01l06nf0112
FujitsuIpcom Ve2 Sc Plus 200 Firmware>= v01l04nf0001, <= v01l06nf0112
FujitsuIpcom Ve2 Sc Plus 220 Firmware>= v01l04nf0001, <= v01l06nf0112
FujitsuIpcom Ex2 In 3200 Firmware>= v01l02nf0001, <= v01l06nf0401
FujitsuIpcom Ex2 In 3200 Firmware>= v01l20nf0001, <= v01l20nf0401
FujitsuIpcom Ex2 In 3200 Firmware>= v02l20nf0001, <= v02l21nf0301
FujitsuIpcom Ex2 In 3500 Firmware>= v01l02nf0001, <= v01l06nf0401
FujitsuIpcom Ex2 In 3500 Firmware>= v01l20nf0001, <= v01l20nf0401
FujitsuIpcom Ex2 In 3500 Firmware>= v02l20nf0001, <= v02l21nf0301
FujitsuIpcom Ex2 Lb 3200 Firmware>= v01l02nf0001, <= v01l06nf0401
FujitsuIpcom Ex2 Lb 3200 Firmware>= v01l20nf0001, <= v01l20nf0401
FujitsuIpcom Ex2 Lb 3200 Firmware>= v02l20nf0001, <= v02l21nf0301
FujitsuIpcom Ex2 Lb 3500 Firmware>= v01l02nf0001, <= v01l06nf0401
FujitsuIpcom Ex2 Lb 3500 Firmware>= v01l20nf0001, <= v01l20nf0401
FujitsuIpcom Ex2 Lb 3500 Firmware>= v02l20nf0001, <= v02l21nf0301
FujitsuIpcom Ex2 Sc 3200 Firmware>= v01l02nf0001, <= v01l06nf0401
FujitsuIpcom Ex2 Sc 3200 Firmware>= v01l20nf0001, <= v01l20nf0401
FujitsuIpcom Ex2 Sc 3200 Firmware>= v02l20nf0001, <= v02l21nf0301
FujitsuIpcom Ex2 Sc 3500 Firmware>= v01l02nf0001, <= v01l06nf0401
FujitsuIpcom Ex2 Sc 3500 Firmware>= v01l20nf0001, <= v01l20nf0401
FujitsuIpcom Ex2 Sc 3500 Firmware>= v02l20nf0001, <= v02l21nf0301
FujitsuIpcom Ex2 Dc 3200 Firmware>= v01l02nf0001, <= v01l06nf0401
FujitsuIpcom Ex2 Dc 3200 Firmware>= v01l20nf0001, <= v01l20nf0401
FujitsuIpcom Ex2 Dc 3200 Firmware>= v02l20nf0001, <= v02l21nf0301
FujitsuIpcom Ex2 Dc 3500 Firmware>= v01l02nf0001, <= v01l06nf0401
FujitsuIpcom Ex2 Dc 3500 Firmware>= v01l20nf0001, <= v01l20nf0401
FujitsuIpcom Ex2 Dc 3500 Firmware>= v02l20nf0001, <= v02l21nf0301

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2024-39921?
Observable timing discrepancy issue exists in IPCOM EX2 Series V01L02NF0001 to V01L06NF0401, V01L20NF0001 to V01L20NF0401, V02L20NF0001 to V02L21NF0301, and IPCOM VE2 Series V01L04NF0001 to V01L06NF0112. If this vulnerability is exploited, some of the encrypted communication may be decrypted by an attacker who can obtain the contents of the communication.
How severe is CVE-2024-39921?
CVE-2024-39921 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 0.43% probability of exploitation in the next 30 days.
How do I fix CVE-2024-39921?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2024-39921?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST