Known Vulnerabilities for products from Fujitsu

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Fujitsu".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Additional devices specifications by Fujitsu can be found at device.report : Fujitsu

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2023-39903 json An issue was discovered in Fujitsu Software Infrastructure Manager (ISM) before 2.8.0.061. The ismsnap component (in this spe... 5 - MEDIUM 2023-08-07 2023-08-11
CVE-2023-39379 json Fujitsu Software Infrastructure Manager (ISM) stores sensitive information at the product's maintenance data (ismsnap) in cle... 7.5 - HIGH 2023-08-04 2023-08-09
CVE-2023-38555 json Authentication bypass vulnerability in Fujitsu network devices Si-R series and SR-M series allows a network-adjacent unauthen... 8.8 - HIGH 2023-07-26 2023-08-03
CVE-2023-38433 json Fujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticated at... 7.5 - HIGH 2023-07-26 2023-11-07
CVE-2023-22377 json Improper restriction of XML external entity reference (XXE) vulnerability exists in tsClinical Define.xml Generator all versi... 7.4 - HIGH 2023-02-15 2023-02-23
CVE-2023-4096 json Weak password recovery mechanism vulnerability in Fujitsu Arconte Áurea version 1.5.0.0, which exploitation could allow an ... 8.2 - HIGH 2023-09-19 2023-09-21
CVE-2023-4095 json User enumeration vulnerability in Arconte Áurea 1.5.0.0 version. The exploitation of this vulnerability could allow an attac... 5.3 - MEDIUM 2023-09-19 2023-09-21
CVE-2023-4094 json ARCONTE Aurea's authentication system, in its 1.5.0.0 version, could allow an attacker to make incorrect access requests in o... 8.2 - HIGH 2023-09-19 2023-09-21
CVE-2023-4093 json Reflected and persistent XSS vulnerability in Arconte Áurea, in its 1.5.0.0 version. The exploitation of this vulnerability ... 6.1 - MEDIUM 2023-09-19 2023-09-21
CVE-2023-4092 json SQL injection vulnerability in Arconte Áurea, in its 1.5.0.0 version. The exploitation of this vulnerability could allow an ... 9.8 - CRITICAL 2023-09-19 2023-09-21
CVE-2022-31795 json An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerabilit... 9.8 - CRITICAL 2022-06-20 2022-06-27
CVE-2022-31794 json An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerabilit... 9.8 - CRITICAL 2022-06-20 2022-06-27
CVE-2022-29516 json The web console of FUJITSU Network IPCOM series (IPCOM EX2 IN(3200, 3500), IPCOM EX2 LB(1100, 3200, 3500), IPCOM EX2 SC(1100,... 9.8 - CRITICAL 2022-05-18 2022-06-01
CVE-2022-28806 json An issue was discovered on certain Fujitsu LIEFBOOK devices (A3510, U9310, U7511/U7411/U7311, U9311, E5510/E5410, U7510/U7410... 7.8 - HIGH 2022-05-04 2022-05-18
CVE-2022-27089 json In Fujitsu PlugFree Network <= 7.3.0.3, an Unquoted service path in PFNService.exe software allows a local attacker to potent... 7.8 - HIGH 2022-04-11 2022-04-15
CVE-2021-20722 json Untrusted search path vulnerability in the installers of ScanSnap Manager prior to versions V7.0L20 and the Software Download... 7.8 - HIGH 2021-05-24 2022-05-03
CVE-2021-3326 json The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the... 7.5 - HIGH 2021-01-27 2023-11-07
CVE-2020-29127 json An issue was discovered on Fujitsu Eternus Storage DX200 S4 devices through 2020-11-25. After logging into the portal as a ro... 9.8 - CRITICAL 2020-11-30 2020-12-03
CVE-2020-17457 json Fujitsu ServerView Suite iRMC before 9.62F allows XSS. An authenticated attacker can store an XSS payload in the PSCU_FILE_IN... 5.4 - MEDIUM 2021-03-17 2021-03-25
CVE-2020-13817 json ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or sys... 7.4 - HIGH 2020-06-04 2022-03-29

Known software with vulnerabilities from Fujitsu

Type Vendor Product Version
HardwareFujitsuArrows Kiss F-03d-
HardwareFujitsuArrows Me F-11d-
HardwareFujitsuArrows Nx F005-f-
HardwareFujitsuArrows Nx F05-f-
Operating
System
FujitsuArrows Nx F05-f Firmware-
HardwareFujitsuArrows Tab Lte F-01d-
ApplicationFujitsuCardminderv3.2l10
HardwareFujitsuCelsius-
Operating
System
FujitsuCelsius Firmware-
HardwareFujitsuEternus Storage Dx200 S4-
Operating
System
FujitsuEternus Storage Dx200 S4 Firmware-
HardwareFujitsuF-12c-
HardwareFujitsuGp7000f-
Operating
System
FujitsuGp7000f Firmware-
HardwareFujitsuGps-
Operating
System
FujitsuGps Firmware-
HardwareFujitsuGranpower 5000-
Operating
System
FujitsuGranpower 5000 Firmware-
ApplicationFujitsuInterstage Application Development Cycle Manager10.0
ApplicationFujitsuInterstage Application Server10.0.0