[Japanese]
|
JVNDB-2023-002022
|
Multiple vulnerabilities in FUJI ELECTRIC FRENIC RHC Loader
|
FRENIC RHC Loader provided by FUJI ELECTRIC CO., LTD. contains multiple vulnerabilities listed below.
* Stack-based buffer overflow (CWE-121) - CVE-2023-29160
* Out-of-bounds read (CWE-125) - CVE-2023-29167
* Improper restriction of XML external entity reference (CWE-611) - CVE-2023-29498
Michael Heinzl reported these vulnerabilities to JPCERT/CC.
JPCERT/CC coordinated with the developer.
|
CVSS V3 Severity: Base Metrics 7.8 (High) [Other]
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
The above CVSS base scores have been assigned for CVE-2023-29160
|
CVSS V3 Severity:
Base Metrics7.8 (High) [Other]
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
The above CVSS base scores have been assigned for CVE-2023-29167
|
CVSS V3 Severity:
Base Metrics5.5 (Medium) [Other]
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
The above CVSS base scores have been assigned for CVE-2023-29498
|
|
Fuji Electric Co., Ltd.
- FRENIC RHC Loader v1.1.0.3 and earlier
|
|
CVE-2023-29160, CVE-2023-29167
If a user opens a specially crafted FNE file, sensitive information on the system where the affected product is installed may be disclosed or arbitrary code may be executed.
CVE-2023-29498
If a user opens a specially crafted project file, sensitive information on the system where the affected product is installed may be disclosed.
|
[Update the software]
Update the software to the latest version according to the information provided by the developer.
|
Fuji Electric Co., Ltd.
|
- Stack-based Buffer Overflow(CWE-121) [Other]
- Out-of-bounds Read(CWE-125) [Other]
- Improper Restriction of XML External Entity Reference(CWE-611) [Other]
|
- CVE-2023-29160
- CVE-2023-29167
- CVE-2023-29498
|
- JVN : JVNVU#97809354
- National Vulnerability Database (NVD) : CVE-2023-29160
- National Vulnerability Database (NVD) : CVE-2023-29167
- National Vulnerability Database (NVD) : CVE-2023-29498
|
- [2023/06/05]
Web page was published
- [2024/04/18]
References : Contents were added
|