Record summary

CVE-2023-38433 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Fujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize or reboot the products, and as a result, terminate the video transmission. Affected products and versions are as follows: IP-HE950E firmware versions V01L001 to V01L053, IP-HE950D firmware versions V01L001 to V01L053, IP-HE900E firmware versions V01L001 to V01L010, IP-HE900D firmware versions V01L001 to V01L004, IP-900E / IP-920E firmware versions V01L001 to V02L061, IP-900D / IP-900ⅡD / IP-920D firmware versions V01L001 to V02L061, IP-90 firmware versions V01L001 to V01L013, and IP-9610 firmware versions V01L001 to V02L007.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Aug 17, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 23, 2024 · Source: CVE List

Affected products and versions

Showing 12 of 20
ProductSourceVersion rangeStatus
CVE Listfirmware versions V01L001 to V01L013affected
CVE Listfirmware versions V01L001 to V02L061affected
CVE Listfirmware versions V01L001 to V02L061affected
CVE Listfirmware versions V01L001 to V02L007affected
CVE Listfirmware versions V01L001 to V01L004affected
CVE Listfirmware versions V01L001 to V01L010affected
CVE Listfirmware versions V01L001 to V01L053affected
CVE Listfirmware versions V01L001 to V01L053affected

Default status: unknown

CVE ListV01L001 to ≤ V01L013affected

Default status: unknown

CVE Listv01l001 to ≤ V02L061affected

Default status: unknown

CVE Listv01l001 to ≤ V02L061affected

Default status: unknown

CVE Listv01l001 to ≤ V02L061affected

Nuclei templates

1
ProjectDiscoveryHIGHFujitsu IP Series - Hardcoded CredentialsCVSS 7.5

Fujitsu Real-time Video Transmission Gear “IP series” use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize or reboot the products, and as a result, terminate the video transmission. The credentials cannot be changed by the end-user and provide administrative access to the devices.

Impact

Successful exploitation of this vulnerability could lead to unauthorized access to the device, potentially resulting in further compromise of the network.

Remediation

Apply the latest security patches and updates from the vendor to address this vulnerability.

WeaknessesCWE-798
AuthorsAdnaneKhan
Template tagscve2023cvefujitsuip-seriesvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CPE: cpe:2.3:o:fujitsu:ip-he950e_firmware:*:*:*:*:*:*:*:*
Shodan: "Server: thttpd/2.25b 29dec2003" content-length:1133
Shodan: "server: thttpd/2.25b 29dec2003" content-length:1133

Source: ProjectDiscovery

References

3