PT-2024-9130 · Fuji Electric · V-Simulator 5

Kimiya

·

Published

2024-11-26

·

Updated

2024-12-03

·

CVE-2024-11802

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Fuji Electric Tellus Lite V-Simulator 5 version V8
Description: The issue is a stack-based buffer overflow vulnerability in the V-Simulator 5 component, specifically in the parsing of V8 files. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Tellus Lite. User interaction is required to exploit this vulnerability, as the target must visit a malicious page or open a malicious file. The problem results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
Recommendations: As a temporary workaround, consider disabling the parsing of V8 files in the V-Simulator 5 component until a patch is available. Restrict access to the V-Simulator 5 component to minimize the risk of exploitation. Avoid opening malicious files or visiting malicious pages to prevent exploitation of this vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-10817
CVE-2024-11802
ZDI-24-1628

Affected Products

V-Simulator 5