PT-2023-5954 · Fujitsu · Ip-9610+10
Published
2023-07-26
·
Updated
2023-09-06
·
CVE-2023-38433
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Fujitsu Real-time Video Transmission Gear "IP series" versions V01L001 to V02L061
Fujitsu IP-HE950E firmware versions V01L001 to V01L053
Fujitsu IP-HE950D firmware versions V01L001 to V01L053
Fujitsu IP-HE900E firmware versions V01L001 to V01L010
Fujitsu IP-HE900D firmware versions V01L001 to V01L004
Fujitsu IP-900E / IP-920E firmware versions V01L001 to V02L061
Fujitsu IP-900D / IP-900ⅡD / IP-920D firmware versions V01L001 to V02L061
Fujitsu IP-90 firmware versions V01L001 to V01L013
Fujitsu IP-9610 firmware versions V01L001 to V02L007
Description
The issue is related to the use of hard-coded credentials in the microprogram software of Fujitsu's IP series devices for real-time video viewing. This may allow a remote unauthenticated attacker to initialize or reboot the products and terminate video transmission.
Recommendations
For Fujitsu IP-HE950E firmware versions V01L001 to V01L053, update the firmware to a version that does not use hard-coded credentials.
For Fujitsu IP-HE950D firmware versions V01L001 to V01L053, update the firmware to a version that does not use hard-coded credentials.
For Fujitsu IP-HE900E firmware versions V01L001 to V01L010, update the firmware to a version that does not use hard-coded credentials.
For Fujitsu IP-HE900D firmware versions V01L001 to V01L004, update the firmware to a version that does not use hard-coded credentials.
For Fujitsu IP-900E / IP-920E firmware versions V01L001 to V02L061, update the firmware to a version that does not use hard-coded credentials.
For Fujitsu IP-900D / IP-900ⅡD / IP-920D firmware versions V01L001 to V02L061, update the firmware to a version that does not use hard-coded credentials.
For Fujitsu IP-90 firmware versions V01L001 to V01L013, update the firmware to a version that does not use hard-coded credentials.
For Fujitsu IP-9610 firmware versions V01L001 to V02L007, update the firmware to a version that does not use hard-coded credentials.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fujitsu Real-Time Video Transmission Gear "Ip Series"
Ip-90
Ip-900D
Ip-900E
Ip-920D
Ip-920E
Ip-9610
Ip-He900D
Ip-He900E
Ip-He950D
Ip-He950E