Impact
The vulnerability is a missing authentication requirement for certain configuration functions on the FA‑50 system. An attacker with access to the vessel's internal network can use the settings interface to modify configuration parameters without proper verification, as documented. This flaw correlates with CWE‑306 and permits an attacker to change operational settings that may affect performance, safety, or communication.
Affected Systems
Affecting all variants of Furuno Electric Co., Ltd.'s FA‑50. No specific version range is provided, so every released FA‑50 iteration is susceptible. The flaw is present across all versions and is not limited to a particular firmware or software update.
Risk and Exploitability
The CVSS base score of 8.7 indicates a high severity. EPSS data is not available, so the likelihood of exploitation is unclear, but the vulnerability is exploitable by any internal actor, such as crew or third‑party maintenance personnel. It is not listed in the CISA KEV catalog, but the combination of a high CVSS and internal access capabilities raises the risk substantially. Until a vendor patch is released, the system should be protected through segmentation, restricted access, and monitoring of configuration changes.
OpenCVE Enrichment