Out-of-bounds write in V-Server Lite and Tellus Lite V-Simulator - CVE-2021-38419
Published: October 27, 2021 / Updated: October 28, 2021
V-Server Lite
Tellus Lite V-Simulator
Fuji Electric
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error within the parsing of V9 files in the V-Simulator module. A remote attacker can create a specially crafted file, trick the victim into opening it using the affected software, trigger out-of-bounds write and execute arbitrary code on the target system.