|
[Japanese]
|
JVNDB-2026-030097
|
FURUNO ELECTRIC FA-50 CLASS B AIS TRANSPONDER uses hard-coded credentials and misses authentication for additional configuration
|
FA-50 CLASS B AIS TRANSPONDER provided by FURUNO ELECTRIC CO., LTD. contains the following vulnerabilities.- Use of hard-coded credentials (CWE-798) - CVE-2026-59769
- The CVSS evaluation above assumes that an attacker who knows the credentials and has access to the network to which the device is connected to operates, using that credentials, the settings screen and alter the identification number etc.
- Missing authentication for critical function (CWE-306) - CVE-2026-67578
Souvik Kandar reported these issues to CISA ICS. At the request of the developer and CISA ICS, JPCERT/CC coordinated with the developer.
|
CVSS V3 Severity: Base Metrics 9.1 (Critical) [Other]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: High
The above CVSS base scores have been assigned for CVE-2026-59769 |
CVSS v3 Severity Base Metrics:7.5 (High) [Other]- Access Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact(C): None
- Integrity Impact(I): High
- Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-67578
|
|
FURUNO ELECTRIC CO., LTD.
|
|
- An attacker, who knows the credentials and has access to the in-vessel network to which the device is connected to, may operate the settings screen using that credentials to alter the settings of the device (CVE-2026-59769).
- Moreover, some additional configuration may be changed on the management screen without authentication (CVE-2026-67578).
|
Production of this product ended in October 2020, and software updates will no longer be provided. The vendor recommends to the product users the following measures.
[Apply the Workaround] - To prevent unauthorized access, the vessel on which the product is installed should be properly locked and managed
- Do not connect the product directly to the internet
[Switch to the successor product]
The successor product (FA-70) is not affected by these vulnerabilities.
|
FURUNO ELECTRIC CO., LTD.
|
- Missing Authentication for Critical Function(CWE-306) [Other]
- Use of Hard-coded Credentials(CWE-798) [Other]
|
- CVE-2026-59769
- CVE-2026-67578
|
- JVN : JVNVU#95422936
- ICS-CERT ADVISORY : ICSA-26-237-07
|
- [2026/08/26]
Web page was published
|