Lucene search

K
cveIcscertCVE-2018-14790
HistoryOct 01, 2018 - 1:29 p.m.

CVE-2018-14790

2018-10-0113:29:00
CWE-126
CWE-125
icscert
web.nvd.nist.gov
32
cve-2018-14790
fuji electric
frenic loader
v3.3
v7.3.4.1a
buffer over-read
remote code execution
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.008

Percentile

81.6%

Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA, FRENIC-Ace. A buffer over-read vulnerability may allow remote code execution on the device.

Affected configurations

Nvd
Node
fujielectricfrenic_loader_3.3_firmwareMatch7.3.4.1a
AND
fujielectricfrenic-aceMatch-
OR
fujielectricfrenic-ecoMatch-
OR
fujielectricfrenic-megaMatch-
OR
fujielectricfrenic-mini\(c1\)Match-
OR
fujielectricfrenic-mini\(c2\)Match-
OR
fujielectricfrenic-multiMatch-
VendorProductVersionCPE
fujielectricfrenic_loader_3.3_firmware7.3.4.1acpe:2.3:o:fujielectric:frenic_loader_3.3_firmware:7.3.4.1a:*:*:*:*:*:*:*
fujielectricfrenic-ace-cpe:2.3:h:fujielectric:frenic-ace:-:*:*:*:*:*:*:*
fujielectricfrenic-eco-cpe:2.3:h:fujielectric:frenic-eco:-:*:*:*:*:*:*:*
fujielectricfrenic-mega-cpe:2.3:h:fujielectric:frenic-mega:-:*:*:*:*:*:*:*
fujielectricfrenic-mini\(c1\)-cpe:2.3:h:fujielectric:frenic-mini\(c1\):-:*:*:*:*:*:*:*
fujielectricfrenic-mini\(c2\)-cpe:2.3:h:fujielectric:frenic-mini\(c2\):-:*:*:*:*:*:*:*
fujielectricfrenic-multi-cpe:2.3:h:fujielectric:frenic-multi:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "FRENIC LOADER of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA, FRENIC-Ace",
    "vendor": "Fuji Electric",
    "versions": [
      {
        "status": "affected",
        "version": "v3.3 v7.3.4.1a"
      }
    ]
  }
]

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.008

Percentile

81.6%

Related for CVE-2018-14790