Improper authentication vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the affected products/versions, see the detailed information provided by the vendor. Note that NR4H, NR8H, NR16H series and DR-16F, DR-8F, DR-4F, DR-16H, DR-8H, DR-4H, DR-4M41 series are no longer supported, therefore updates for those products are not provided.
Conclusion & alert: CVE-2023-38585 is rated High Risk (65/100): CVSS High severity, with medium exploitation likelihood (EPSS 2.01%). Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-18 | 1.61% | 2.01% | +0.39% |
| 2 | 2025-11-21 | 0.78% | 1.61% | +0.83% |
| 3 | 2025-11-18 | — | 0.78% | — |
Full EPSS history (10 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| cbc | nr4h_firmware | — | cpe:2.3:o:cbc:nr4h_firmware:-:*:*:*:*:*:*:* |
| cbc | nr8h_firmware | — | cpe:2.3:o:cbc:nr8h_firmware:-:*:*:*:*:*:*:* |
| cbc | nr16h_firmware | — | cpe:2.3:o:cbc:nr16h_firmware:-:*:*:*:*:*:*:* |
| cbc | dr-16f42a_firmware | — | cpe:2.3:o:cbc:dr-16f42a_firmware:-:*:*:*:*:*:*:* |
| cbc | dr-16f45at_firmware | — | cpe:2.3:o:cbc:dr-16f45at_firmware:-:*:*:*:*:*:*:* |
| cbc | dr-8f42a_firmware | — | cpe:2.3:o:cbc:dr-8f42a_firmware:-:*:*:*:*:*:*:* |
| cbc | dr-8f45at_firmware | — | cpe:2.3:o:cbc:dr-8f45at_firmware:-:*:*:*:*:*:*:* |
| cbc | dr-4fx1_firmware | — | cpe:2.3:o:cbc:dr-4fx1_firmware:-:*:*:*:*:*:*:* |
| cbc | dr-16h_firmware | — | cpe:2.3:o:cbc:dr-16h_firmware:-:*:*:*:*:*:*:* |
| cbc | dr-8h_firmware | — | cpe:2.3:o:cbc:dr-8h_firmware:-:*:*:*:*:*:*:* |
| cbc | dr-4h_firmware | — | cpe:2.3:o:cbc:dr-4h_firmware:-:*:*:*:*:*:*:* |
| cbc | drh8-4m41-a_firmware | — | cpe:2.3:o:cbc:drh8-4m41-a_firmware:-:*:*:*:*:*:*:* |
| cbc | nr8-4m71_firmware | — | cpe:2.3:o:cbc:nr8-4m71_firmware:-:*:*:*:*:*:*:* |
| cbc | nr8-8m72_firmware | — | cpe:2.3:o:cbc:nr8-8m72_firmware:-:*:*:*:*:*:*:* |
| cbc | nr-16m_firmware | — | cpe:2.3:o:cbc:nr-16m_firmware:-:*:*:*:*:*:*:* |
| cbc | nr-16f85-8pra_firmware | — | cpe:2.3:o:cbc:nr-16f85-8pra_firmware:-:*:*:*:*:*:*:* |
| cbc | nr-16f82-16p_firmware | — | cpe:2.3:o:cbc:nr-16f82-16p_firmware:-:*:*:*:*:*:*:* |
| cbc | nr-4f_firmware | — | cpe:2.3:o:cbc:nr-4f_firmware:-:*:*:*:*:*:*:* |
| cbc | nr-8f_firmware | — | cpe:2.3:o:cbc:nr-8f_firmware:-:*:*:*:*:*:*:* |
| cbc | dr-16m52_firmware | — | cpe:2.3:o:cbc:dr-16m52_firmware:-:*:*:*:*:*:*:* |
| cbc | dr-16m52-av_firmware | — | cpe:2.3:o:cbc:dr-16m52-av_firmware:-:*:*:*:*:*:*:* |
| cbc | dr-8m52-av_firmware | — | cpe:2.3:o:cbc:dr-8m52-av_firmware:-:*:*:*:*:*:*:* |
| cbc | dr-4m51-av_firmware | — | cpe:2.3:o:cbc:dr-4m51-av_firmware:-:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://download.ganzsecurity.pl/ | Product |
| https://ganzsecurity.com/release/1578/digimasterpixelmaster-security-notice | Vendor Advisory |
| https://jvn.jp/en/vu/JVNVU92545432/ | Third Party Advisory |