{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-47397","assignerOrgId":"ede6fdc4-6654-4307-a26d-3331c018e2ce","state":"PUBLISHED","assignerShortName":"jpcert","dateReserved":"2024-12-10T07:10:15.313Z","datePublished":"2024-12-18T06:35:16.031Z","dateUpdated":"2024-12-18T14:58:49.381Z"},"containers":{"cna":{"affected":[{"vendor":"FXC Inc.","product":"AE1021","versions":[{"version":"firmware versions 2.0.10 and earlier","status":"affected"}]},{"vendor":"FXC Inc.","product":"AE1021PE","versions":[{"version":"firmware versions 2.0.10 and earlier","status":"affected"}]}],"descriptions":[{"lang":"en","value":"Weak authentication issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 and earlier. If this vulnerability is exploited, the authentication may be bypassed with an undocumented specific string."}],"problemTypes":[{"descriptions":[{"description":"Weak authentication","lang":"en-US","cweId":"CWE-1390","type":"CWE"}]}],"references":[{"url":"https://www.fxc.jp/news/20241213"},{"url":"https://jvn.jp/en/vu/JVNVU91084137/"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en-US","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","baseSeverity":"HIGH","baseScore":7.5,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}}],"providerMetadata":{"orgId":"ede6fdc4-6654-4307-a26d-3331c018e2ce","shortName":"jpcert","dateUpdated":"2024-12-18T06:35:16.031Z"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-12-18T14:58:36.329686Z","id":"CVE-2024-47397","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-12-18T14:58:49.381Z"}}]}}