PT-2024-3882 · Fuji Electric · Monitouch V-Sft

Kimiy

·

Published

2024-05-30

·

Updated

2024-06-03

·

CVE-2024-34171

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Fuji Electric Monitouch V-SFT versions V9C through V10
Description: The issue is related to a stack-based buffer overflow, which could allow an attacker to execute arbitrary code. This overflow is associated with the parsing of files in the Monitouch V-SFT software.
Recommendations: For Fuji Electric Monitouch V-SFT versions V9C through V10, consider disabling the file parsing functionality as a temporary workaround until a patch is available. Restrict access to the vulnerable file parsing module to minimize the risk of exploitation. Avoid using the vulnerable versions for critical operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04285
CVE-2024-34171
ZDI-24-530
ZDI-24-532
ZDI-24-533
ZDI-24-534
ZDI-24-535

Affected Products

Monitouch V-Sft