FA-50 all versions miss authentication for some configuration.
An attacker with access to the vessel's internal network can manipulate the product's settings screen to alter some configuration parameters.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | FA‑50 Authentication Bypass Allowing Configuration Changes via Internal Network |
Tue, 25 Aug 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FA-50 all versions miss authentication for some configuration. An attacker with access to the vessel's internal network can manipulate the product's settings screen to alter some configuration parameters. | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: jpcert
Published: 2026-08-25T07:42:26.438Z
Updated: 2026-08-25T14:51:55.561Z
Reserved: 2026-08-04T01:31:35.564Z
Link: CVE-2026-67578
Updated: 2026-08-25T14:46:35.989Z
Status : Received
Published: 2026-08-25T08:18:10.360
Modified: 2026-08-25T15:16:37.230
Link: CVE-2026-67578
No data.