CVE-2023-38555

Description

Authentication bypass vulnerability in Fujitsu network devices Si-R series and SR-M series allows a network-adjacent unauthenticated attacker to obtain, change, and/or reset configuration settings of the affected products. Affected products and versions are as follows: Si-R 30B all versions, Si-R 130B all versions, Si-R 90brin all versions, Si-R570B all versions, Si-R370B all versions, Si-R220D all versions, Si-R G100 V02.54 and earlier, Si-R G200 V02.54 and earlier, Si-R G100B V04.12 and earlier, Si-R G110B V04.12 and earlier, Si-R G200B V04.12 and earlier, Si-R G210 V20.52 and earlier, Si-R G211 V20.52 and earlier, Si-R G120 V20.52 and earlier, Si-R G121 V20.52 and earlier, and SR-M 50AP1 all versions.

Category

8.8
CVSS
Severity: High
CVSS 3.1 •
EPSS 0.05%
Vendor Advisory fujitsu.com
Affected: Fujitsu Limited Si-R 30B
Affected: Fujitsu Limited Si-R 130B
Affected: Fujitsu Limited Si-R 90brin
Affected: Fujitsu Limited Si-R570B
Affected: Fujitsu Limited Si-R370B
Affected: Fujitsu Limited Si-R220D
Affected: Fujitsu Limited Si-R G100
Affected: Fujitsu Limited Si-R G200
Affected: Fujitsu Limited Si-R G100B
Affected: Fujitsu Limited Si-R G110B
Affected: Fujitsu Limited Si-R G200B
Affected: Fujitsu Limited Si-R G210
Affected: Fujitsu Limited Si-R G211
Affected: Fujitsu Limited Si-R G120
Affected: Fujitsu Limited Si-R G121
Affected: Fujitsu Limited SR-M 50AP1
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2023-38555?
CVE-2023-38555 has been scored as a high severity vulnerability.
How to fix CVE-2023-38555?
To fix CVE-2023-38555, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2023-38555 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2023-38555 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2023-38555?
CVE-2023-38555 affects Fujitsu Limited Si-R 30B, Fujitsu Limited Si-R 130B, Fujitsu Limited Si-R 90brin, Fujitsu Limited Si-R570B, Fujitsu Limited Si-R370B, Fujitsu Limited Si-R220D, Fujitsu Limited Si-R G100, Fujitsu Limited Si-R G200, Fujitsu Limited Si-R G100B, Fujitsu Limited Si-R G110B, Fujitsu Limited Si-R G200B, Fujitsu Limited Si-R G210, Fujitsu Limited Si-R G211, Fujitsu Limited Si-R G120, Fujitsu Limited Si-R G121, Fujitsu Limited SR-M 50AP1.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.