Vulnerability Description
Authentication bypass vulnerability in Fujitsu network devices Si-R series and SR-M series allows a network-adjacent unauthenticated attacker to obtain, change, and/or reset configuration settings of the affected products. Affected products and versions are as follows: Si-R 30B all versions, Si-R 130B all versions, Si-R 90brin all versions, Si-R570B all versions, Si-R370B all versions, Si-R220D all versions, Si-R G100 V02.54 and earlier, Si-R G200 V02.54 and earlier, Si-R G100B V04.12 and earlier, Si-R G110B V04.12 and earlier, Si-R G200B V04.12 and earlier, Si-R G210 V20.52 and earlier, Si-R G211 V20.52 and earlier, Si-R G120 V20.52 and earlier, Si-R G121 V20.52 and earlier, and SR-M 50AP1 all versions.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fujitsu | Si-R 30B Firmware | All versions |
| Fujitsu | Si-R 30B | - |
| Fujitsu | Si-R 130B Firmware | All versions |
| Fujitsu | Si-R 130B | - |
| Fujitsu | Si-R 90Brin Firmware | All versions |
| Fujitsu | Si-R 90Brin | - |
| Fujitsu | Si-R570B Firmware | All versions |
| Fujitsu | Si-R570B | - |
| Fujitsu | Si-R370B Firmware | All versions |
| Fujitsu | Si-R370B | - |
| Fujitsu | Si-R220D Firmware | All versions |
| Fujitsu | Si-R220D | - |
| Fujitsu | Si-R G100 Firmware | <= 02.54 |
| Fujitsu | Si-R G100 | - |
| Fujitsu | Si-R G200 Firmware | <= 02.54 |
| Fujitsu | Si-R G200 | - |
| Fujitsu | Si-R G100B Firmware | <= 04.12 |
| Fujitsu | Si-R G100B | - |
| Fujitsu | Si-R G110B Firmware | <= 04.12 |
| Fujitsu | Si-R G110B | - |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/vu/JVNVU96643580/Third Party Advisory
- https://www.fujitsu.com/jp/products/network/support/2023/fjlan-01/Vendor Advisory
- https://jvn.jp/en/vu/JVNVU96643580/Third Party Advisory
- https://www.fujitsu.com/jp/products/network/support/2023/fjlan-01/Vendor Advisory
FAQ
What is CVE-2023-38555?
CVE-2023-38555 is a vulnerability with a CVSS score of 8.8 (HIGH). Authentication bypass vulnerability in Fujitsu network devices Si-R series and SR-M series allows a network-adjacent unauthenticated attacker to obtain, change, and/or reset configuration settings of ...
How severe is CVE-2023-38555?
CVE-2023-38555 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-38555?
Check the references section above for vendor advisories and patch information. Affected products include: Fujitsu Si-R 30B Firmware, Fujitsu Si-R 30B, Fujitsu Si-R 130B Firmware, Fujitsu Si-R 130B, Fujitsu Si-R 90Brin Firmware.