← Back
CVE-2026-67578
high
CVSS 7.5
FA-50 all versions miss authentication for some configuration. An attacker with access to the...
Summary
FA-50 all versions miss authentication for some configuration. An attacker with access to the...
AI summary openai / gpt-4o
FA-50の全バージョンにおいて、一部の設定に対する認証が欠落している脆弱性が存在します。この問題により、攻撃者は船内ネットワークにアクセスすることで、製品の設定画面を操作して設定パラメータを変更することが可能です。
❓ What is the problem
一部の設定に認証が欠落していること。
📍 Affected scope
FA-50の全バージョン。
🔥 Severity
攻撃者は内部ネットワークから設定パラメータを変更可能であり、高いリスクを伴う。
🔧 How to fix
設定画面への認証機構の追加。
🛡️ Workaround
船内ネットワークへのアクセス制御を強化する。
🔍 Detection
設定パラメータに予期しない変更がないか定期的に監視する。