Published:2024/01/09 Last Updated:2024/01/09
JVNVU#92102247
Multiple vulnerabilities in Panasonic Control FPWIN Pro7
Overview
Control FPWIN Pro7 provided by Panasonic contains multiple vulnerabilities.
Products Affected
- Control FPWIN Pro7 Ver. 7.7.0.0 and earlier
Description
Control FPWIN Pro7 provided by Panasonic contains multiple vulnerabilities listed below.
- Stack-based Buffer Overflow (CWE-121) - CVE-2023-6314
CVSS v3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Base Score: 7.8 - Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) - CVE-2023-6315
CVSS v3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Base Score: 7.8
Impact
By having a user open a specially crafted file, arbitrary code may be executed.
Solution
Update the software
Update the software to the latest version according to the information provided by the developer.
Vendor Status
Vendor | Link |
Panasonic | Programming software Control FPWIN Pro |
Vulnerability Advisory List |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Michael Heinzl reported these vulnerabilities to the developer and coordinated. After the coordination was completed, Panasonic reported the case to JPCERT/CC to notify users of the solutions through JVN.