Published:2024/01/09  Last Updated:2024/01/09

JVNVU#92102247
Multiple vulnerabilities in Panasonic Control FPWIN Pro7

Overview

Control FPWIN Pro7 provided by Panasonic contains multiple vulnerabilities.

Products Affected

  • Control FPWIN Pro7 Ver. 7.7.0.0 and earlier

Description

Control FPWIN Pro7 provided by Panasonic contains multiple vulnerabilities listed below.

  • Stack-based Buffer Overflow (CWE-121) - CVE-2023-6314
    CVSS v3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Base Score: 7.8
  • Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) - CVE-2023-6315
    CVSS v3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Base Score: 7.8

Impact

By having a user open a specially crafted file, arbitrary code may be executed.

Solution

Update the software
Update the software to the latest version according to the information provided by the developer.

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Michael Heinzl reported these vulnerabilities to the developer and coordinated. After the coordination was completed, Panasonic reported the case to JPCERT/CC to notify users of the solutions through JVN.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE
JVN iPedia