CVE-2023-39341
"FFRI yarai", "FFRI yarai Home and Business Edition" and their OEM products handle exceptional conditions improperly, which may lead to denial-of-service (DoS) condition. Affected products and versions are as follows: FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0, FFRI yarai Home and Business Edition version 1.4.0, InfoTrace Mark II Malware Protection (Mark II Zerona) versions 3.0.1 to 3.2.2, Zerona / Zerona PLUS versions 3.2.32 to 3.2.36, ActSecure χ versions 3.4.0 to 3.4.6 and 3.5.0, Dual Safe Powered by FFRI yarai version 1.4.1, EDR Plus Pack (Bundled FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0), and EDR Plus Pack Cloud (Bundled FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0).
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
- Puntuación base: 3.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.29%
- Percentil entre todas las CVEs puntuadas: 20
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (8)
CWE
- CWE-755
Referencias
- https://jvn.jp/en/jp/JVN42527152/
- https://www.ffri.jp/security-info/index.htm
- https://www.skyseaclientview.net/news/230807_01/
- https://www.soliton.co.jp/support/zerona_notice_2023.html
- https://www.sourcenext.com/support/i/2023/230718_01
- https://www.support.nec.co.jp/View.aspx?id=3140109240
- https://jvn.jp/en/jp/JVN42527152/
- https://www.ffri.jp/security-info/index.htm
- https://www.skyseaclientview.net/news/230807_01/
- https://www.soliton.co.jp/support/zerona_notice_2023.html
- https://www.sourcenext.com/support/i/2023/230718_01
- https://www.support.nec.co.jp/View.aspx?id=3140109240
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-39341",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-39341",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-10-17T14:20:33.187569Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.3,
"attackVector": "LOCAL",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "vultures@jpcert.or.jp",
"affectedData": [
{
"vendor": "FFRI Security, Inc. ",
"product": "FFRI yarai",
"versions": [
{
"status": "affected",
"version": "versions 3.4.0 to 3.4.6 and 3.5.0"
}
]
},
{
"vendor": "FFRI Security, Inc. ",
"product": "FFRI yarai Home and Business Edition",
"versions": [
{
"status": "affected",
"version": "version 1.4.0"
}
]
},
{
"vendor": "Soliton Systems K.K.",
"product": "InfoTrace Mark II Malware Protection (Mark II Zerona)",
"versions": [
{
"status": "affected",
"version": "versions 3.0.1 to 3.2.2"
}
]
},
{
"vendor": "Soliton Systems K.K.",
"product": "Zerona / Zerona PLUS",
"versions": [
{
"status": "affected",
"version": " versions 3.2.32 to 3.2.36"
}
]
},
{
"vendor": "NEC Corporation",
"product": "ActSecure χ",
"versions": [
{
"status": "affected",
"version": "versions 3.4.0 to 3.4.6 and 3.5.0"
}
]
},
{
"vendor": "SOURCENEXT CORPORATION ",
"product": "Dual Safe Powered by FFRI yarai",
"versions": [
{
"status": "affected",
"version": "version 1.4.1"
}
]
},
{
"vendor": "Sky Co., Ltd.",
"product": "EDR Plus Pack",
"versions": [
{
"status": "affected",
"version": "Bundled FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0"
}
]
},
{
"vendor": "Sky Co., Ltd.",
"product": "EDR Plus Pack Cloud",
"versions": [
{
"status": "affected",
"version": "Bundled FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0"
}
]
}
]
}
],
"published": "2023-08-09T03:15:43.870",
"references": [
{
"url": "https://jvn.jp/en/jp/JVN42527152/",
"tags": [
"Third Party Advisory"
],
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://www.ffri.jp/security-info/index.htm",
"tags": [
"Vendor Advisory"
],
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://www.skyseaclientview.net/news/230807_01/",
"tags": [
"Third Party Advisory"
],
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://www.soliton.co.jp/support/zerona_notice_2023.html",
"tags": [
"Third Party Advisory"
],
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://www.sourcenext.com/support/i/2023/230718_01",
"tags": [
"Third Party Advisory"
],
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://www.support.nec.co.jp/View.aspx?id=3140109240",
"tags": [
"Permissions Required"
],
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://jvn.jp/en/jp/JVN42527152/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.ffri.jp/security-info/index.htm",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.skyseaclientview.net/news/230807_01/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.soliton.co.jp/support/zerona_notice_2023.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.sourcenext.com/support/i/2023/230718_01",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.support.nec.co.jp/View.aspx?id=3140109240",
"tags": [
"Permissions Required"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-755"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "\"FFRI yarai\", \"FFRI yarai Home and Business Edition\" and their OEM products handle exceptional conditions improperly, which may lead to denial-of-service (DoS) condition. \r\nAffected products and versions are as follows: FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0, FFRI yarai Home and Business Edition version 1.4.0, InfoTrace Mark II Malware Protection (Mark II Zerona) versions 3.0.1 to 3.2.2, Zerona / Zerona PLUS versions 3.2.32 to 3.2.36, ActSecure χ versions 3.4.0 to 3.4.6 and 3.5.0, Dual Safe Powered by FFRI yarai version 1.4.1, EDR Plus Pack (Bundled FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0), and EDR Plus Pack Cloud (Bundled FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0)."
}
],
"lastModified": "2026-06-17T06:12:05.860",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ffri:dual_safe:1.4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "20EF112B-225F-4880-B7A0-6C4AE9945E2D"
},
{
"criteria": "cpe:2.3:a:ffri:ffri_yarai:*:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A44E7B03-2512-498B-9D21-38B19A97A336",
"versionEndIncluding": "3.4.6",
"versionStartIncluding": "3.4.0"
},
{
"criteria": "cpe:2.3:a:ffri:ffri_yarai:1.4.0:*:*:*:home_and_business:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4AFD814C-9F3F-4E56-A24F-5650A171E3E9"
},
{
"criteria": "cpe:2.3:a:ffri:ffri_yarai:3.5.0:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "41317723-07EF-4911-B340-9D32B71F897C"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:soliton:infotrace_mark_ii_malware_protection:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AB0991A6-F9EA-4ABD-BAEB-DD39EF595291",
"versionEndIncluding": "3.2.2",
"versionStartIncluding": "3.0.1"
},
{
"criteria": "cpe:2.3:a:soliton:zerona:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E74EF415-FD34-44F9-B77C-1A221E29C73F",
"versionEndIncluding": "3.2.36",
"versionStartIncluding": "3.2.32"
},
{
"criteria": "cpe:2.3:a:soliton:zerona_plus:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F55621CC-7C6C-4837-92EC-AE7A52260D17",
"versionEndIncluding": "3.2.36",
"versionStartIncluding": "3.2.32"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nec:actsecure_x_managed_security_service:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4419A375-07A3-4AC9-8DF7-3EB6AE6E6BC6",
"versionEndIncluding": "3.4.6",
"versionStartIncluding": "3.4.0"
},
{
"criteria": "cpe:2.3:a:nec:actsecure_x_managed_security_service:3.5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "78EEA207-0F94-4DA9-AF86-8507571D378A"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:skygroup:edr_plus_pack:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "862B4D6B-D084-4393-8B96-108F676BADA3",
"versionEndIncluding": "3.4.6",
"versionStartIncluding": "3.4.0"
},
{
"criteria": "cpe:2.3:a:skygroup:edr_plus_pack:3.5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2D3D3C5F-A7D1-428C-8A27-A10062C53FF2"
},
{
"criteria": "cpe:2.3:a:skygroup:edr_plus_pack_cloud:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "20F70879-2C78-47E4-AE0B-B4EAD74D1C4C",
"versionEndIncluding": "3.4.6",
"versionStartIncluding": "3.4.0"
},
{
"criteria": "cpe:2.3:a:skygroup:edr_plus_pack_cloud:3.5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6CF54F00-D3EA-4E54-8590-8CA0BD37FF17"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "vultures@jpcert.or.jp"
}