PT-2024-9130 · Fuji Electric · V-Simulator 5
Kimiya
·
Published
2024-11-26
·
Updated
2024-12-03
·
CVE-2024-11802
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
Fuji Electric Tellus Lite V-Simulator 5 version V8
Description:
The issue is a stack-based buffer overflow vulnerability in the V-Simulator 5 component, specifically in the parsing of V8 files. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Tellus Lite. User interaction is required to exploit this vulnerability, as the target must visit a malicious page or open a malicious file. The problem results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
Recommendations:
As a temporary workaround, consider disabling the parsing of V8 files in the V-Simulator 5 component until a patch is available. Restrict access to the V-Simulator 5 component to minimize the risk of exploitation. Avoid opening malicious files or visiting malicious pages to prevent exploitation of this vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Memory Corruption
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
V-Simulator 5