CVE-2023-38433
fujitsu ip-he950e_firmware Use of Hard-coded Credentials
Record summary
CVE-2023-38433 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Fujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize or reboot the products, and as a result, terminate the video transmission. Affected products and versions are as follows: IP-HE950E firmware versions V01L001 to V01L053, IP-HE950D firmware versions V01L001 to V01L053, IP-HE900E firmware versions V01L001 to V01L010, IP-HE900D firmware versions V01L001 to V01L004, IP-900E / IP-920E firmware versions V01L001 to V02L061, IP-900D / IP-900ⅡD / IP-920D firmware versions V01L001 to V02L061, IP-90 firmware versions V01L001 to V01L013, and IP-9610 firmware versions V01L001 to V02L007.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Aug 17, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 23, 2024 · Source: CVE List
Affected products and versions
Showing 12 of 20| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | firmware versions V01L001 to V01L013 | affected | |
IP-900D / IP-900ⅡD / IP-920DBrowse Fujitsu Limited / IP-900D / IP-900ⅡD / IP-920D | CVE List | firmware versions V01L001 to V02L061 | affected |
IP-900E / IP-920EBrowse Fujitsu Limited / IP-900E / IP-920E | CVE List | firmware versions V01L001 to V02L061 | affected |
| CVE List | firmware versions V01L001 to V02L007 | affected | |
IP-HE900DBrowse Fujitsu Limited / IP-HE900D | CVE List | firmware versions V01L001 to V01L004 | affected |
IP-HE900EBrowse Fujitsu Limited / IP-HE900E | CVE List | firmware versions V01L001 to V01L010 | affected |
IP-HE950DBrowse Fujitsu Limited / IP-HE950D | CVE List | firmware versions V01L001 to V01L053 | affected |
IP-HE950EBrowse Fujitsu Limited / IP-HE950E | CVE List | firmware versions V01L001 to V01L053 | affected |
Default status: unknown | CVE List | V01L001 to ≤ V01L013 | affected |
ip-900d_firmwareBrowse fujitsu / ip-900d_firmwareDefault status: unknown | CVE List | v01l001 to ≤ V02L061 | affected |
ip-900e_firmwareBrowse fujitsu / ip-900e_firmwareDefault status: unknown | CVE List | v01l001 to ≤ V02L061 | affected |
ip-900iid_firmwareBrowse fujitsu / ip-900iid_firmwareDefault status: unknown | CVE List | v01l001 to ≤ V02L061 | affected |
Nuclei templates
1ProjectDiscoveryHIGHFujitsu IP Series - Hardcoded CredentialsCVSS 7.5
Fujitsu Real-time Video Transmission Gear “IP series” use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize or reboot the products, and as a result, terminate the video transmission. The credentials cannot be changed by the end-user and provide administrative access to the devices.
Impact
Successful exploitation of this vulnerability could lead to unauthorized access to the device, potentially resulting in further compromise of the network.
Remediation
Apply the latest security patches and updates from the vendor to address this vulnerability.
Source: ProjectDiscovery