SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-38585

Improper authentication vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings.

HIGH 8.8EPSS 1.07%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.07%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Improper authentication vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the affected products/versions, see the detailed information provided by the vendor. Note that NR4H, NR8H, NR16H series and DR-16F, DR-8F, DR-4F, DR-16H, DR-8H, DR-4H, DR-4M41 series are no longer supported, therefore updates for those products are not provided.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
1.07% probability · 63th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
cbc/nr4h firmware · cbc/nr8h firmware · cbc/nr16h firmware · cbc/dr-16f42a firmware · cbc/dr-16f45at firmware · cbc/dr-8f42a firmware · cbc/dr-8f45at firmware · cbc/dr-4fx1 firmware · cbc/dr-16h firmware · cbc/dr-8h firmware · cbc/dr-4h firmware · cbc/drh8-4m41-a firmware · cbc/nr8-4m71 firmware · cbc/nr8-8m72 firmware · cbc/nr-16m firmware · cbc/nr-16f85-8pra firmware · cbc/nr-16f82-16p firmware · cbc/nr-4f firmware · cbc/nr-8f firmware · cbc/dr-16m52 firmware · +3 more
Source
vultures@jpcert.or.jp

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.