First published: Thu Sep 27 2018(Updated: )
Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA, FRENIC-Ace. The program does not properly check user-supplied comments which may allow for arbitrary remote code execution.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Fujielectric Frenic Loader 3.3 Firmware | =7.3.4.1a | |
Fujielectric Frenic-ace | ||
Fujielectric Frenic-eco | ||
Fujielectric Frenic-mega | ||
Fujielectric Frenic-mini(c1) | ||
Fujielectric Frenic-mini(c2) | ||
Fujielectric Frenic-multi |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-14802 is rated as critical due to its potential for arbitrary remote code execution.
To mitigate CVE-2018-14802, update to the latest version of Fuji Electric FRENIC LOADER firmware that addresses this vulnerability.
CVE-2018-14802 affects Fuji Electric FRENIC LOADER v3.3, specifically version 7.3.4.1a.
CVE-2018-14802 can allow attackers to execute arbitrary code remotely, potentially compromising system integrity.
Yes, the vulnerable devices include FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA, and FRENIC-Ace.