Improper Restriction of Operations in TELLUS by Fujielectric
CVE-2023-47580

7.8HIGH

What is CVE-2023-47580?

Multiple improper restriction of operations within the bounds of a memory buffer issues have been identified in TELLUS, affecting versions V4.0.17.0 and earlier and TELLUS Lite V4.0.17.0 and earlier. Users opening specially crafted files, such as X1, V8, or V9 files, may risk disclosing sensitive information or executing arbitrary code. This vulnerability highlights the need for stringent security measures in software handling user inputs.

Affected Version(s)

TELLUS V4.0.17.0 and earlier

TELLUS Lite V4.0.17.0 and earlier

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-47580 : Improper Restriction of Operations in TELLUS by Fujielectric