CVE-2024-36454
Estado: AplazadaMedia (5.3)—
Use of uninitialized resource issue exists in IPCOM EX2 Series (V01L0x Series) V01L07NF0201 and earlier, and IPCOM VE2 Series V01L07NF0201 and earlier. If this vulnerability is exploited, the system may be rebooted or suspended by receiving a specially crafted packet.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.46%
- Percentil entre todas las CVEs puntuadas: 38
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-908
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-36454",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-36454",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-07-16T18:17:41.103809Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "vultures@jpcert.or.jp",
"affectedData": [
{
"vendor": "Fsas Technologies Inc.",
"product": "IPCOM EX2 Series (V01L0x Series)",
"versions": [
{
"status": "affected",
"version": "V01L07NF0201 and earlier"
}
]
},
{
"vendor": "Fsas Technologies Inc.",
"product": "IPCOM VE2 Series",
"versions": [
{
"status": "affected",
"version": "V01L07NF0201 and earlier"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:o:fujitsu:ipcom_ex2_in_3200_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:fujitsu:ipcom_ex2_in_3500_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:fujitsu:ipcom_ex2_lb_3200_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:fujitsu:ipcom_ex2_lb_3500_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:fujitsu:ipcom_ex2_sc_3200_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:fujitsu:ipcom_ex2_sc_3500_firmware:-:*:*:*:*:*:*:*"
],
"vendor": "fujitsu",
"product": "ipcom_ex2_sc_3500_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "01l07nf0201"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:fujitsu:ipcom_ve2_ls_plus_100_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:fujitsu:ipcom_ve2_ls_plus_200_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:fujitsu:ipcom_ve2_ls_plus2_200_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:fujitsu:ipcom_ve2_ls_plus_220_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:o:fujitsu:ipcom_ve2_ls_plus2_220_firmware:-:*:*:*:*:*:*:*"
],
"vendor": "fujitsu",
"product": "ipcom_ve2_ls_plus2_220_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "01l07nf0201"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-06-12T06:15:09.127",
"references": [
{
"url": "https://jvn.jp/en/jp/JVN25594256/",
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://www.fujitsu.com/jp/products/network/support/2024/ipcom-02/",
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://jvn.jp/en/jp/JVN25594256/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.fujitsu.com/jp/products/network/support/2024/ipcom-02/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-908"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Use of uninitialized resource issue exists in IPCOM EX2 Series (V01L0x Series) V01L07NF0201 and earlier, and IPCOM VE2 Series V01L07NF0201 and earlier. If this vulnerability is exploited, the system may be rebooted or suspended by receiving a specially crafted packet."
},
{
"lang": "es",
"value": "El problema del uso de recursos no inicializados existe en IPCOM EX2 Series (V01L0x Series) V01L07NF0201 y anteriores, y en IPCOM VE2 Series V01L07NF0201 y anteriores. Si se aprovecha esta vulnerabilidad, el sistema puede reiniciarse o suspenderse al recibir un paquete especialmente manipulado."
}
],
"lastModified": "2026-06-17T07:36:45.390",
"sourceIdentifier": "vultures@jpcert.or.jp"
}