|
[Japanese]
|
JVNDB-2026-009720
|
Multiple vulnerabilities in FUJI Electric V-SFT (April 2026)
|
V-SFT provided by FUJI ELECTRIC CO., LTD. contains multiple vulnerabilities listed below.- Stack-based buffer overflow in VS6ComFile!CV7BaseMap::WriteV7DataToRom (CWE-121) - CVE-2026-32925
- Out-of-bounds read in VS6ComFile!load_link_inf (CWE-125) - CVE-2026-32926
- Out-of-bounds read in VS6MemInIF!set_temp_type_default (CWE-125) - CVE-2026-32927
- Stack-based buffer overflow in VS6ComFile!CSaveData::_conv_AnimationItem (CWE-121) - CVE-2026-32928
- Out-of-bounds read in VS6ComFile!get_macro_mem_COM (CWE-125) - CVE-2026-32929
Michael Heinzl reported this vulnerability to JPCERT/CC.
JPCERT/CC coordinated with the developer.
|
CVSS V3 Severity: Base Metrics 7.8 (High) [Other]
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
The above CVSS base scores have been assigned for CVE-2026-32925 |
CVSS v3 Severity Base Metrics:7.8 (High) [Other]- Access Vector: Local
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Confidentiality Impact(C): High
- Integrity Impact(I): High
- Availability Impact(A): High
The above CVSS base scores have been assigned for CVE-2026-32926
|
CVSS v3 Severity Base Metrics:7.8 (High) [Other]- Access Vector: Local
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Confidentiality Impact(C): High
- Integrity Impact(I): High
- Availability Impact(A): High
The above CVSS base scores have been assigned for CVE-2026-32927
|
CVSS v3 Severity Base Metrics:7.8 (High) [Other]- Access Vector: Local
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Confidentiality Impact(C): High
- Integrity Impact(I): High
- Availability Impact(A): High
The above CVSS base scores have been assigned for CVE-2026-32928
|
CVSS v3 Severity Base Metrics:7.8 (High) [Other]- Access Vector: Local
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Confidentiality Impact(C): High
- Integrity Impact(I): High
- Availability Impact(A): High
The above CVSS base scores have been assigned for CVE-2026-32929
|
|
Fuji Electric Co., Ltd.
- V-SFT ver 6.2.10.0 and prior
|
|
Opening a crafted V7 file may lead to information exposure or arbitrary code execution on the affected product.
|
[Update the software]
Update the software to the latest version according to the information provided by the developer.
|
Fuji Electric Co., Ltd.
|
- Stack-based Buffer Overflow(CWE-121) [Other]
- Out-of-bounds Read(CWE-125) [Other]
|
- CVE-2026-32925
- CVE-2026-32926
- CVE-2026-32927
- CVE-2026-32928
- CVE-2026-32929
|
- JVN : JVNVU#90448293
|
- [2026/04/02]
Web page was published
|