S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-38433 Scanner

Detects 'Hard-Coded Credentials' vulnerability in Fujitsu Limited IP-HE950E, IP-HE950D, IP-HE900E, IP-HE900D, IP-900E / IP-920E, IP-900D / IP-900ⅡD / IP-920D, IP-90, IP-9610 affects v. IP-HE950E firmware V01L001 to V01L053, IP-HE950D firmware V01L001 to V01L053, IP-HE900E firmware V01L001 to V01L010, IP-HE900D firmware V01L001 to V01L004, IP-900E / IP-920E firmware V01L001 to V02L061, IP-900D / IP-900ⅡD / IP-920D firmware V01L001 to V02L061, IP-90 firmware V01L001 to V01L013, and IP-9610 firmware V01L001 to V02L007..

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-38433
7.5
CVSS

Fujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize or reboot the products, and as a result, terminate the video transmission. Affected products and versions are as follows: IP-HE950E firmware versions V01L001 to V01L053, IP-HE950D firmware versions V01L001 to V01L053, IP-HE900E firmware versions V01L001 to V01L010, IP-HE900D firmware versions V01L001 to V01L004, IP-900E / IP-920E firmware versions V01L001 to V02L061, IP-900D / IP-900ⅡD / IP-920D firmware versions V01L001 to V02L061, IP-90 firmware versions V01L001 to V01L013, and IP-9610 firmware versions V01L001 to V02L007.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
IP-HE950Eby Fujitsu Limited
firmware versions V01L001 to V01L053
IP-HE950Dby Fujitsu Limited
firmware versions V01L001 to V01L053
IP-HE900Eby Fujitsu Limited
firmware versions V01L001 to V01L010
IP-HE900Dby Fujitsu Limited
firmware versions V01L001 to V01L004
Updated Aug 22, 2026View on NVD →
Detail

The Fujitsu Limited IP series is a range of real-time video transmission gear designed for use in various industries. These products are used to transmit high-definition video content over long distances through Ethernet networks. Specifically, the IP-HE950E, IP-HE950D, IP-HE900E, IP-HE900D, IP-900E / IP-920E, IP-900D / IP-900ⅡD / IP-920D, IP-90, and IP-9610 models are utilized in surveillance systems, broadcasting stations, and video-conferencing setups.

The CVE-2023-38433 vulnerability has been detected in the Fujitsu Real-time Video Transmission Gear "IP series." This vulnerability arises from the use of hard-coded credentials that allow unauthenticated remote attackers to trigger reboot or initialization of the product, causing the termination of the video transmission. The hard-coded credentials are often included by manufacturers for administrative purposes and can become a serious security risk if an attacker gains access to them.

Exploiting this vulnerability can lead to serious consequences, including unauthorized access to sensitive information transmitted via the video transmission gear. Attackers can also use the gear as a launchpad for launching more extensive attacks on the target network. This vulnerability is a severe threat to the privacy and security of any video transmission that relies on the Fujitsu IP series.

Those who are concerned about the vulnerability in their digital assets can quickly learn about them through the pro features of the s4e.io platform. This platform is a comprehensive resource for information on the latest security threats and vulnerabilities affecting organizations worldwide. With its user-friendly interface and expert analysis, this platform makes it easy to stay up-to-date on the latest security threats, protect digital assets, and take proactive steps towards improved cybersecurity.

 

REFERENCES

Solution Advice

There is a need to take appropriate precautions to protect against vulnerabilities like CVE-2023-38433. The following bullet list shows some of the possible measures that can be taken to protect Fujitsu's IP series gear from attacks:

  • Upgrade the firmware on all the affected products.
  • Implement a strong and unique password policy.
  • Consider implementing two-factor authentication.
  • Ensure that all ports used by the video transmission equipment are properly secured.
  • Train all employees on the importance of cybersecurity and how to identify suspicious activities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.