Home
HIGH: 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NHIGH: 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HDefault status
unaffected
Any version before 1.4.0.1
affected
1.4.0.1
unaffected
Description
Fuji Electric FRENIC-Loader 4 is vulnerable to a deserialization of untrusted data when importing a file through a specified window, which may allow an attacker to execute arbitrary code.
Problem types
CWE-502 Deserialization of Untrusted Data
Product status
Any version before 1.4.0.1
1.4.0.1
Credits
kimiya working with Trend Micro Zero Day Initiative reported this vulnerability to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-245-02
felib.fujielectric.co.jp/...3970-e560-4961-8013-fc72be43681a