Severity

High

Analysis Summary

CVE-2023-47584 CVSS:7.8

Fuji Electric V-Server and V-Server Lite could allow a remote attacker to execute arbitrary code on the system, caused by an out-of-bounds write. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system.

CVE-2023-47585 CVSS:7.8

Fuji Electric V-Server and V-Server Lite could allow a remote attacker to execute arbitrary code on the system, caused by an out-of-bounds read. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system.

CVE-2023-47586 CVSS:7.8

Fuji Electric V-Server and V-Server Lite are vulnerable to a heap-based buffer overflow, caused by improper bounds checking. By persuading a victim to open a specially crafted file, a remote attacker could overflow a buffer and execute arbitrary code on the system.

Impact

  • Buffer Overflow
  • Code Execution

Indicators Of Compromise

CVE

  • CVE-2023-47584
  • CVE-2023-47585
  • CVE-2023-47586

Affected Vendors

Fuji Electric

Affected Products

  • Fuji Electric V-Sever 4.0.18.0
  • Fuji Electric V-Sever 4.0.18.0 Lite

Remediation

Refer to Fuji Electric Security Advisory for patch, upgrade or suggested workaround information.

Fuji Electric Security Advisory