CVE-2024-39921

Observable timing discrepancy issue exists in IPCOM EX2 Series V01L02NF0001 to V01L06NF0401, V01L20NF0001 to V01L20NF0401, V02L20NF0001 to V02L21NF0301, and IPCOM VE2 Series V01L04NF0001 to V01L06NF0112. If this vulnerability is exploited, some of the encrypted communication may be decrypted by an attacker who can obtain the contents of the communication.
References
Link Resource
https://jvn.jp/en/jp/JVN29238389/ Mitigation Third Party Advisory
https://www.fujitsu.com/jp/products/network/support/2024/ipcom-04/ Mitigation Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:fujitsu:ipcom_ve2_ls_100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ve2_ls_100:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:fujitsu:ipcom_ve2_ls_200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ve2_ls_200:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:fujitsu:ipcom_ve2_ls_220_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ve2_ls_220:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:fujitsu:ipcom_ve2_ls_plus_100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ve2_ls_plus_100:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:fujitsu:ipcom_ve2_ls_plus_200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ve2_ls_plus_200:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:fujitsu:ipcom_ve2_ls_plus_220_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ve2_ls_plus_220:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:fujitsu:ipcom_ve2_ls_plus2_200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ve2_ls_plus2_200:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:fujitsu:ipcom_ve2_ls_plus2_220_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ve2_ls_plus2_220:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:fujitsu:ipcom_ve2_sc_plus_100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ve2_sc_plus_100:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:fujitsu:ipcom_ve2_sc_plus_200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ve2_sc_plus_200:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:fujitsu:ipcom_ve2_sc_plus_220_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ve2_sc_plus_220:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
OR cpe:2.3:o:fujitsu:ipcom_ex2_in_3200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ex2_in_3200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ex2_in_3200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ex2_in_3200:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
OR cpe:2.3:o:fujitsu:ipcom_ex2_in_3500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ex2_in_3500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ex2_in_3500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ex2_in_3500:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
OR cpe:2.3:o:fujitsu:ipcom_ex2_lb_3200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ex2_lb_3200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ex2_lb_3200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ex2_lb_3200:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
OR cpe:2.3:o:fujitsu:ipcom_ex2_lb_3500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ex2_lb_3500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ex2_lb_3500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ex2_lb_3500:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
OR cpe:2.3:o:fujitsu:ipcom_ex2_sc_3200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ex2_sc_3200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ex2_sc_3200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ex2_sc_3200:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
OR cpe:2.3:o:fujitsu:ipcom_ex2_sc_3500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ex2_sc_3500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ex2_sc_3500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ex2_sc_3500:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
OR cpe:2.3:o:fujitsu:ipcom_ex2_dc_3200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ex2_dc_3200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ex2_dc_3200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ex2_dc_3200:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
OR cpe:2.3:o:fujitsu:ipcom_ex2_dc_3500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ex2_dc_3500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ex2_dc_3500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ex2_dc_3500:-:*:*:*:*:*:*:*

History

19 Sep 2024, 14:59

Type Values Removed Values Added
CPE cpe:2.3:h:fujitsu:ipcom_ve2_ls_plus_220:-:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ve2_ls_100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ex2_dc_3200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ve2_sc_plus_100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ex2_sc_3200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ve2_sc_plus_200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ve2_ls_plus_200:-:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ex2_in_3500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ex2_lb_3500:-:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ve2_sc_plus_200:-:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ex2_sc_3200:-:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ex2_sc_3500:-:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ex2_dc_3500:-:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ve2_ls_plus2_200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ve2_ls_100:-:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ex2_lb_3500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ve2_ls_220:-:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ex2_lb_3200:-:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ve2_sc_plus_220:-:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ex2_in_3500:-:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ve2_ls_plus_200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ve2_ls_plus2_220_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ex2_dc_3500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ex2_in_3200:-:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ex2_lb_3200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ve2_ls_plus_100:-:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ex2_dc_3200:-:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ve2_ls_plus2_200:-:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ve2_ls_plus_220_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ve2_ls_220_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ex2_in_3200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ex2_sc_3500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ve2_sc_plus_100:-:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ve2_ls_200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ve2_ls_200:-:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ve2_ls_plus_100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fujitsu:ipcom_ve2_ls_plus2_220:-:*:*:*:*:*:*:*
cpe:2.3:o:fujitsu:ipcom_ve2_sc_plus_220_firmware:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-203
First Time Fujitsu ipcom Ex2 Lb 3500 Firmware
Fujitsu ipcom Ex2 Sc 3200 Firmware
Fujitsu ipcom Ex2 Dc 3500 Firmware
Fujitsu ipcom Ve2 Ls Plus 100
Fujitsu ipcom Ve2 Ls 100
Fujitsu ipcom Ve2 Ls Plus2 220
Fujitsu ipcom Ve2 Ls 200 Firmware
Fujitsu ipcom Ve2 Ls Plus 220
Fujitsu ipcom Ve2 Ls 220 Firmware
Fujitsu ipcom Ve2 Sc Plus 220
Fujitsu ipcom Ex2 In 3500 Firmware
Fujitsu ipcom Ve2 Ls Plus2 220 Firmware
Fujitsu ipcom Ve2 Sc Plus 200
Fujitsu ipcom Ve2 Ls Plus 200
Fujitsu ipcom Ve2 Sc Plus 200 Firmware
Fujitsu ipcom Ex2 In 3200
Fujitsu ipcom Ve2 Ls Plus2 200
Fujitsu ipcom Ve2 Ls 220
Fujitsu ipcom Ve2 Sc Plus 220 Firmware
Fujitsu ipcom Ex2 Dc 3200
Fujitsu ipcom Ex2 In 3200 Firmware
Fujitsu ipcom Ex2 Lb 3500
Fujitsu ipcom Ex2 Dc 3200 Firmware
Fujitsu ipcom Ex2 Sc 3200
Fujitsu ipcom Ve2 Ls Plus 200 Firmware
Fujitsu ipcom Ex2 Dc 3500
Fujitsu ipcom Ve2 Ls 100 Firmware
Fujitsu ipcom Ex2 In 3500
Fujitsu ipcom Ve2 Ls Plus 220 Firmware
Fujitsu ipcom Ve2 Sc Plus 100
Fujitsu ipcom Ex2 Sc 3500
Fujitsu ipcom Ve2 Ls Plus2 200 Firmware
Fujitsu ipcom Ve2 Ls 200
Fujitsu ipcom Ex2 Sc 3500 Firmware
Fujitsu ipcom Ve2 Sc Plus 100 Firmware
Fujitsu
Fujitsu ipcom Ve2 Ls Plus 100 Firmware
Fujitsu ipcom Ex2 Lb 3200
Fujitsu ipcom Ex2 Lb 3200 Firmware
References () https://jvn.jp/en/jp/JVN29238389/ - () https://jvn.jp/en/jp/JVN29238389/ - Mitigation, Third Party Advisory
References () https://www.fujitsu.com/jp/products/network/support/2024/ipcom-04/ - () https://www.fujitsu.com/jp/products/network/support/2024/ipcom-04/ - Mitigation, Vendor Advisory

04 Sep 2024, 13:05

Type Values Removed Values Added
Summary
  • (es) Existe un problema de discrepancia de tiempo observable en las series IPCOM EX2 V01L02NF0001 a V01L06NF0401, V01L20NF0001 a V01L20NF0401, V02L20NF0001 a V02L21NF0301 y en las series IPCOM VE2 V01L04NF0001 a V01L06NF0112. Si se explota esta vulnerabilidad, un atacante puede descifrar parte de la comunicación cifrada y obtener el contenido de la misma.

04 Sep 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-04 03:15

Updated : 2024-09-19 14:59


NVD link : CVE-2024-39921

Mitre link : CVE-2024-39921

CVE.ORG link : CVE-2024-39921


JSON object : View

Products Affected

fujitsu

  • ipcom_ex2_lb_3200_firmware
  • ipcom_ex2_sc_3200_firmware
  • ipcom_ve2_ls_plus2_220
  • ipcom_ve2_sc_plus_220_firmware
  • ipcom_ex2_dc_3500_firmware
  • ipcom_ve2_sc_plus_100
  • ipcom_ex2_lb_3500
  • ipcom_ve2_sc_plus_200
  • ipcom_ve2_ls_plus2_220_firmware
  • ipcom_ex2_in_3500
  • ipcom_ve2_ls_200
  • ipcom_ve2_ls_plus2_200_firmware
  • ipcom_ve2_ls_100_firmware
  • ipcom_ve2_ls_220_firmware
  • ipcom_ex2_dc_3200_firmware
  • ipcom_ve2_ls_plus2_200
  • ipcom_ex2_dc_3200
  • ipcom_ex2_in_3200_firmware
  • ipcom_ve2_ls_200_firmware
  • ipcom_ve2_ls_100
  • ipcom_ve2_ls_plus_200_firmware
  • ipcom_ex2_sc_3500
  • ipcom_ve2_ls_plus_100
  • ipcom_ex2_in_3200
  • ipcom_ex2_lb_3200
  • ipcom_ex2_in_3500_firmware
  • ipcom_ve2_ls_plus_220_firmware
  • ipcom_ve2_sc_plus_200_firmware
  • ipcom_ve2_sc_plus_220
  • ipcom_ve2_ls_220
  • ipcom_ve2_ls_plus_220
  • ipcom_ve2_ls_plus_200
  • ipcom_ex2_dc_3500
  • ipcom_ex2_sc_3500_firmware
  • ipcom_ve2_ls_plus_100_firmware
  • ipcom_ex2_lb_3500_firmware
  • ipcom_ex2_sc_3200
  • ipcom_ve2_sc_plus_100_firmware
CWE
CWE-203

Observable Discrepancy