« Volver al listado

CVE-2023-39341

Estado: ModificadaBaja (3.3)—

"FFRI yarai", "FFRI yarai Home and Business Edition" and their OEM products handle exceptional conditions improperly, which may lead to denial-of-service (DoS) condition. Affected products and versions are as follows: FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0, FFRI yarai Home and Business Edition version 1.4.0, InfoTrace Mark II Malware Protection (Mark II Zerona) versions 3.0.1 to 3.2.2, Zerona / Zerona PLUS versions 3.2.32 to 3.2.36, ActSecure χ versions 3.4.0 to 3.4.6 and 3.5.0, Dual Safe Powered by FFRI yarai version 1.4.1, EDR Plus Pack (Bundled FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0), and EDR Plus Pack Cloud (Bundled FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (8)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-39341",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-39341",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-17T14:20:33.187569Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.3,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "FFRI Security, Inc. ",
          "product": "FFRI yarai",
          "versions": [
            {
              "status": "affected",
              "version": "versions 3.4.0 to 3.4.6 and 3.5.0"
            }
          ]
        },
        {
          "vendor": "FFRI Security, Inc. ",
          "product": "FFRI yarai Home and Business Edition",
          "versions": [
            {
              "status": "affected",
              "version": "version 1.4.0"
            }
          ]
        },
        {
          "vendor": "Soliton Systems K.K.",
          "product": "InfoTrace Mark II Malware Protection (Mark II Zerona)",
          "versions": [
            {
              "status": "affected",
              "version": "versions 3.0.1 to 3.2.2"
            }
          ]
        },
        {
          "vendor": "Soliton Systems K.K.",
          "product": "Zerona / Zerona PLUS",
          "versions": [
            {
              "status": "affected",
              "version": " versions 3.2.32 to 3.2.36"
            }
          ]
        },
        {
          "vendor": "NEC Corporation",
          "product": "ActSecure χ",
          "versions": [
            {
              "status": "affected",
              "version": "versions 3.4.0 to 3.4.6 and 3.5.0"
            }
          ]
        },
        {
          "vendor": "SOURCENEXT CORPORATION ",
          "product": "Dual Safe Powered by FFRI yarai",
          "versions": [
            {
              "status": "affected",
              "version": "version 1.4.1"
            }
          ]
        },
        {
          "vendor": "Sky Co., Ltd.",
          "product": "EDR Plus Pack",
          "versions": [
            {
              "status": "affected",
              "version": "Bundled FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0"
            }
          ]
        },
        {
          "vendor": "Sky Co., Ltd.",
          "product": "EDR Plus Pack Cloud",
          "versions": [
            {
              "status": "affected",
              "version": "Bundled FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2023-08-09T03:15:43.870",
  "references": [
    {
      "url": "https://jvn.jp/en/jp/JVN42527152/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.ffri.jp/security-info/index.htm",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.skyseaclientview.net/news/230807_01/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.soliton.co.jp/support/zerona_notice_2023.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.sourcenext.com/support/i/2023/230718_01",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.support.nec.co.jp/View.aspx?id=3140109240",
      "tags": [
        "Permissions Required"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN42527152/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.ffri.jp/security-info/index.htm",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.skyseaclientview.net/news/230807_01/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.soliton.co.jp/support/zerona_notice_2023.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.sourcenext.com/support/i/2023/230718_01",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.support.nec.co.jp/View.aspx?id=3140109240",
      "tags": [
        "Permissions Required"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-755"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "\"FFRI yarai\", \"FFRI yarai Home and Business Edition\" and their OEM products handle exceptional conditions improperly, which may lead to denial-of-service (DoS) condition. \r\nAffected products and versions are as follows: FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0, FFRI yarai Home and Business Edition version 1.4.0, InfoTrace Mark II Malware Protection (Mark II Zerona) versions 3.0.1 to 3.2.2, Zerona / Zerona PLUS versions 3.2.32 to 3.2.36, ActSecure χ versions 3.4.0 to 3.4.6 and 3.5.0, Dual Safe Powered by FFRI yarai version 1.4.1, EDR Plus Pack (Bundled FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0), and EDR Plus Pack Cloud (Bundled FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0)."
    }
  ],
  "lastModified": "2026-06-17T06:12:05.860",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ffri:dual_safe:1.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20EF112B-225F-4880-B7A0-6C4AE9945E2D"
            },
            {
              "criteria": "cpe:2.3:a:ffri:ffri_yarai:*:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A44E7B03-2512-498B-9D21-38B19A97A336",
              "versionEndIncluding": "3.4.6",
              "versionStartIncluding": "3.4.0"
            },
            {
              "criteria": "cpe:2.3:a:ffri:ffri_yarai:1.4.0:*:*:*:home_and_business:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4AFD814C-9F3F-4E56-A24F-5650A171E3E9"
            },
            {
              "criteria": "cpe:2.3:a:ffri:ffri_yarai:3.5.0:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "41317723-07EF-4911-B340-9D32B71F897C"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:soliton:infotrace_mark_ii_malware_protection:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AB0991A6-F9EA-4ABD-BAEB-DD39EF595291",
              "versionEndIncluding": "3.2.2",
              "versionStartIncluding": "3.0.1"
            },
            {
              "criteria": "cpe:2.3:a:soliton:zerona:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E74EF415-FD34-44F9-B77C-1A221E29C73F",
              "versionEndIncluding": "3.2.36",
              "versionStartIncluding": "3.2.32"
            },
            {
              "criteria": "cpe:2.3:a:soliton:zerona_plus:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F55621CC-7C6C-4837-92EC-AE7A52260D17",
              "versionEndIncluding": "3.2.36",
              "versionStartIncluding": "3.2.32"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:nec:actsecure_x_managed_security_service:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4419A375-07A3-4AC9-8DF7-3EB6AE6E6BC6",
              "versionEndIncluding": "3.4.6",
              "versionStartIncluding": "3.4.0"
            },
            {
              "criteria": "cpe:2.3:a:nec:actsecure_x_managed_security_service:3.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "78EEA207-0F94-4DA9-AF86-8507571D378A"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:skygroup:edr_plus_pack:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "862B4D6B-D084-4393-8B96-108F676BADA3",
              "versionEndIncluding": "3.4.6",
              "versionStartIncluding": "3.4.0"
            },
            {
              "criteria": "cpe:2.3:a:skygroup:edr_plus_pack:3.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2D3D3C5F-A7D1-428C-8A27-A10062C53FF2"
            },
            {
              "criteria": "cpe:2.3:a:skygroup:edr_plus_pack_cloud:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20F70879-2C78-47E4-AE0B-B4EAD74D1C4C",
              "versionEndIncluding": "3.4.6",
              "versionStartIncluding": "3.4.0"
            },
            {
              "criteria": "cpe:2.3:a:skygroup:edr_plus_pack_cloud:3.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6CF54F00-D3EA-4E54-8590-8CA0BD37FF17"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}