FUJI Electric V-SFT
cpe:2.3:a:fujielectric:monitouch_v-sft:*:*:*:*:*:*:*, +1 more
- <= 6.2.7.0
A vulnerability allowing out-of-bounds read has been identified in the V-SFT software by Fuji Electric, specifically in version 6.2.7.0 and earlier. This vulnerability resides in the 'VS6ComFile!CSaveData::delete_mem' function. Opening specially crafted V-SFT files can trigger this vulnerability, potentially leading to unauthorized information disclosure, causing the system to experience an abnormal termination (ABEND), and allowing arbitrary code execution.
Exploitation of this vulnerability could result in unauthorized information disclosure, an abnormal system termination (ABEND), and arbitrary code execution.
Users are advised to update the software to the latest version. Improvement information for V-SFT version 6 is available on the Fuji Electric Monitouch website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.