Fujitsu records
81 published records for vendor fujitsu.
Researcher profile
- Entered KEV
- 1 · 1.2%
- Weaponized
- 2 · 2.5%
- Pre-auth RCE
- 8
- With a fix record
- 19.8%
- Median publish → KEV
- 3171 days
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer6
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-287 Improper Authentication3
- CWE-312 Cleartext Storage of Sensitive Information3
The weakness classes this vendor ships most often: where to look.
CWEAll records
81 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2013-2251Weaponized | Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,apache · archiva · CWE-74 | Critical9.8 | KEV | 100.0% | Jul 19, 2013 |
48Plan | CVE-2013-2566Weaponized | The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to oracle · communications application session controller · CWE-326 | Medium5.9 | — | 84.4% | Mar 15, 2013 |
45Plan | CVE-2021-23840Proof of concept | Integer overflow in CipherUpdateopenssl · openssl · CWE-190 | High7.5 | — | 50.7% | Feb 16, 2021 |
42Plan | CVE-2016-8610Proof of concept | A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processiopenssl · openssl · CWE-400 | High7.5 | — | 39.7% | Nov 13, 2017 |
42Plan | CVE-2009-0270No exploit | Stack-based buffer overflow in PXEService.exe in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier allows remote attackers to executfujitsu · systemcastwizard lite · CWE-119 | Critical10.0 | — | 5.5% | Jan 26, 2009 |
41Plan | CVE-2018-1000007No exploit | libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties.haxx · curl | Critical9.8 | — | 8.0% | Jan 24, 2018 |
41Plan | CVE-2008-1040No exploit | Buffer overflow in the Single Sign-On function in Fujitsu Interstage Application Server 8.0.0 through 8.0.3 and 9.0.0, Interstage Studio 8.0fujitsu · interstage application server enterprise · CWE-119 | Critical10.0 | — | 4.6% | Feb 27, 2008 |
41Plan | CVE-2013-7105No exploit | Buffer overflow in the Interstage HTTP Server log functionality, as used in Fujitsu Interstage Application Server 9.0.0, 9.1.0, 9.2.0, 9.3.1fujitsu · interstage application server · CWE-119 | Critical10.0 | — | 1.8% | Dec 14, 2013 |
40Plan | CVE-2019-6111Proof of concept | An issue was discovered in OpenSSH 7.9.openbsd · openssh · CWE-22 | Medium5.9 | — | 58.2% | Jan 31, 2019 |
40Plan | CVE-2020-29127No exploit | An issue was discovered on Fujitsu Eternus Storage DX200 S4 devices through 2020-11-25.fujitsu · eternus storage dx200 s4 firmware · CWE-287 | Critical9.8 | — | 4.5% | Nov 30, 2020 |
40Plan | CVE-2022-31794No exploit | An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04.fujitsu · eternus cs8000 firmware · CWE-78 | Critical9.8 | — | 3.1% | Jun 20, 2022 |
40Plan | CVE-2022-31795No exploit | An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04.fujitsu · eternus cs8000 firmware · CWE-78 | Critical9.8 | — | 3.1% | Jun 20, 2022 |
40Plan | CVE-2019-18200No exploit | An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices.fujitsu · lx390 firmware | Critical9.8 | — | 2.8% | Oct 24, 2019 |
40Plan | CVE-2022-29516No exploit | The web console of FUJITSU Network IPCOM series (IPCOM EX2 IN(3200, 3500), IPCOM EX2 LB(1100, 3200, 3500), IPCOM EX2 SC(1100, 3200, 3500), Ifujitsu · ipcom ex2 nw 1100 firmware · CWE-78 | Critical9.8 | — | 2.2% | May 18, 2022 |
40Plan | CVE-2009-0264No exploit | Buffer overflow in the Registry Setting Tool in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier has unknown impact and attack vectfujitsu · systemcastwizard lite · CWE-119 | Critical10.0 | — | 1.6% | Jan 26, 2009 |
39Monitor | CVE-2023-4092No exploit | SQL injection vulnerability in Fujitsu Arconte Áureafujitsu · arconte aurea · CWE-89 | Critical9.8 | — | 0.7% | Sep 19, 2023 |
38Monitor | CVE-2019-9835No exploit | The receiver (aka bridge) component of Fujitsu Wireless Keyboard Set LX901 GK900 devices allows Keystroke Injection.fujitsu · lx901 firmware | Critical9.6 | — | 0.6% | Mar 15, 2019 |
36Monitor | CVE-2015-2808No exploit | The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initializatiooracle · communications application session controller · CWE-327 | Low3.7 | — | 73.9% | Mar 31, 2015 |
35Monitor | CVE-2023-38555No exploit | Authentication bypass vulnerability in Fujitsu network devices Si-R series and SR-M series allows a network-adjacent unauthenticated attackefujitsu · si-r 30b firmware · CWE-287 | High8.8 | — | 0.4% | Jul 26, 2023 |
34Monitor | CVE-2024-33620No exploit | Absolute path traversal vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR.fsas technologies inc. · fujitsu business application id link manager ii · CWE-36 | High8.6 | — | 0.7% | Jun 18, 2024 |
33Monitor | CVE-2020-8285No exploit | curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.haxx · libcurl · CWE-674 | High7.5 | — | 9.8% | Dec 14, 2020 |
32Monitor | CVE-2018-16156Proof of concept | In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes unauthenticated messafujitsu · paperstream ip \(twain\) · CWE-426 | High7.8 | — | 2.6% | May 17, 2019 |
32Monitor | CVE-2023-4094No exploit | Weak authentication vulnerability in Fujitsu Arconte Áureafujitsu · arconte aurea · CWE-1390 | High8.2 | — | 0.5% | Sep 19, 2023 |
32Monitor | CVE-2023-4096No exploit | Weak password recovery mechanism vulnerability in Fujitsu Arconte Áureafujitsu · arconte aurea · CWE-640 | High8.2 | — | 0.4% | Sep 19, 2023 |
31Monitor | CVE-2007-3011Proof of concept | The DBAsciiAccess CGI Script in the web interface in Fujitsu-Siemens Computers ServerView before 4.50.09 allows remote attackers to execute fujitsu · serverview | High7.5 | — | 4.2% | Jul 5, 2007 |
- CVE-2013-225199Now
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · archivaJul 19, 2013
- CVE-2013-256648Plan
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to
MediumCVSS 5.9WeaponizedEPSS 84%oracle · communications application session controllerMar 15, 2013
- CVE-2021-2384045Plan
Integer overflow in CipherUpdate
HighCVSS 7.5Proof of conceptEPSS 51%openssl · opensslFeb 16, 2021
- CVE-2016-861042Plan
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processi
HighCVSS 7.5Proof of conceptEPSS 40%openssl · opensslNov 13, 2017
- CVE-2009-027042Plan
Stack-based buffer overflow in PXEService.exe in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier allows remote attackers to execut
CriticalCVSS 10.0No exploitEPSS 6%fujitsu · systemcastwizard liteJan 26, 2009
- CVE-2018-100000741Plan
libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties.
CriticalCVSS 9.8No exploitEPSS 8%haxx · curlJan 24, 2018
- CVE-2008-104041Plan
Buffer overflow in the Single Sign-On function in Fujitsu Interstage Application Server 8.0.0 through 8.0.3 and 9.0.0, Interstage Studio 8.0
CriticalCVSS 10.0No exploitEPSS 5%fujitsu · interstage application server enterpriseFeb 27, 2008
- CVE-2013-710541Plan
Buffer overflow in the Interstage HTTP Server log functionality, as used in Fujitsu Interstage Application Server 9.0.0, 9.1.0, 9.2.0, 9.3.1
CriticalCVSS 10.0No exploitEPSS 2%fujitsu · interstage application serverDec 14, 2013
- CVE-2019-611140Plan
An issue was discovered in OpenSSH 7.9.
MediumCVSS 5.9Proof of conceptEPSS 58%openbsd · opensshJan 31, 2019
- CVE-2020-2912740Plan
An issue was discovered on Fujitsu Eternus Storage DX200 S4 devices through 2020-11-25.
CriticalCVSS 9.8No exploitEPSS 4%fujitsu · eternus storage dx200 s4 firmwareNov 30, 2020
- CVE-2022-3179440Plan
An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04.
CriticalCVSS 9.8No exploitEPSS 3%fujitsu · eternus cs8000 firmwareJun 20, 2022
- CVE-2022-3179540Plan
An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04.
CriticalCVSS 9.8No exploitEPSS 3%fujitsu · eternus cs8000 firmwareJun 20, 2022
- CVE-2019-1820040Plan
An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices.
CriticalCVSS 9.8No exploitEPSS 3%fujitsu · lx390 firmwareOct 24, 2019
- CVE-2022-2951640Plan
The web console of FUJITSU Network IPCOM series (IPCOM EX2 IN(3200, 3500), IPCOM EX2 LB(1100, 3200, 3500), IPCOM EX2 SC(1100, 3200, 3500), I
CriticalCVSS 9.8No exploitEPSS 2%fujitsu · ipcom ex2 nw 1100 firmwareMay 18, 2022
- CVE-2009-026440Plan
Buffer overflow in the Registry Setting Tool in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier has unknown impact and attack vect
CriticalCVSS 10.0No exploitEPSS 2%fujitsu · systemcastwizard liteJan 26, 2009
- CVE-2023-409239Monitor
SQL injection vulnerability in Fujitsu Arconte Áurea
CriticalCVSS 9.8No exploitEPSS 1%fujitsu · arconte aureaSep 19, 2023
- CVE-2019-983538Monitor
The receiver (aka bridge) component of Fujitsu Wireless Keyboard Set LX901 GK900 devices allows Keystroke Injection.
CriticalCVSS 9.6No exploitEPSS 1%fujitsu · lx901 firmwareMar 15, 2019
- CVE-2015-280836Monitor
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initializatio
LowCVSS 3.7No exploitEPSS 74%oracle · communications application session controllerMar 31, 2015
- CVE-2023-3855535Monitor
Authentication bypass vulnerability in Fujitsu network devices Si-R series and SR-M series allows a network-adjacent unauthenticated attacke
HighCVSS 8.8No exploitEPSS 0%fujitsu · si-r 30b firmwareJul 26, 2023
- CVE-2024-3362034Monitor
Absolute path traversal vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR.
HighCVSS 8.6No exploitEPSS 1%fsas technologies inc. · fujitsu business application id link manager iiJun 18, 2024
- CVE-2020-828533Monitor
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
HighCVSS 7.5No exploitEPSS 10%haxx · libcurlDec 14, 2020
- CVE-2018-1615632Monitor
In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes unauthenticated messa
HighCVSS 7.8Proof of conceptEPSS 3%fujitsu · paperstream ip \(twain\)May 17, 2019
- CVE-2023-409432Monitor
Weak authentication vulnerability in Fujitsu Arconte Áurea
HighCVSS 8.2No exploitEPSS 0%fujitsu · arconte aureaSep 19, 2023
- CVE-2023-409632Monitor
Weak password recovery mechanism vulnerability in Fujitsu Arconte Áurea
HighCVSS 8.2No exploitEPSS 0%fujitsu · arconte aureaSep 19, 2023
- CVE-2007-301131Monitor
The DBAsciiAccess CGI Script in the web interface in Fujitsu-Siemens Computers ServerView before 4.50.09 allows remote attackers to execute
HighCVSS 7.5Proof of conceptEPSS 4%fujitsu · serverviewJul 5, 2007