Fujitsu Limited Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Fujitsu Limited products.
Products
- FENCE-Explorer for Windows1 vulnerability
- FENCE-Mobile RemoteManager i-FILTER Browser Service1 vulnerability
- FUJITSU Network Edgiot GW1500 (M2M-GW for FENICS)1 vulnerability
- Fujitsu Software Infrastructure Manager Advanced Edition1 vulnerability
- Fujitsu Software Infrastructure Manager Advanced Edition for PRIMEFLEX1 vulnerability
- Fujitsu Software Infrastructure Manager Essential Edition1 vulnerability
- i-FILTER Browser & Cloud MultiAgent for Windows1 vulnerability
- IP-901 vulnerability
- IP-900D / IP-900ⅡD / IP-920D1 vulnerability
- IP-900E / IP-920E1 vulnerability
- IP-96101 vulnerability
- IP-HE900D1 vulnerability
- IP-HE900E1 vulnerability
- IP-HE950D1 vulnerability
- IP-HE950E1 vulnerability
- IPCOM EX2 series, IPCOM EX series, IPCOM VE2 series, and IPCOM VA2/VE1 series1 vulnerability
- Si-R 130B1 vulnerability
- Si-R 30B1 vulnerability
- Si-R 90brin1 vulnerability
- Si-R G1001 vulnerability
- Si-R G100B1 vulnerability
- Si-R G110B1 vulnerability
- Si-R G1201 vulnerability
- Si-R G1211 vulnerability
- Si-R G2001 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-28267MEDIUM | Generated title:Multiple i-FILTER Products Incorrect Default Permissions VulnerabilityMultiple i-フィルター products are configured with improper file access permission settings. Files may be created or overwritten in the system directory or backup directory by a non-administrative user. CWE-276Mar 9, 2026 | CVSS6.8v4.0 | EPSS0.105% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-57846HIGH | Multiple i-フィルター products contain an issue with incorrect default permissions. If this vulnerability is exploited, a local authenticated attacker may replace a service executable on the system where the product is running, potentially allowing arbitrary code execution with SYSTEM privileges. CWE-276Aug 27, 2025 | CVSS8.5v4.0 | EPSS0.15% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-40617MEDIUM | Path traversal vulnerability exists in FUJITSU Network Edgiot GW1500 (M2M-GW for FENICS). If a remote authenticated attacker with User Class privilege sends a specially crafted request to the affected product, access restricted files containing sensitive information may be accessed. As a result, Administrator Class privileges of the product may be hijacked. CWE-22Jul 17, 2024 | CVSS6.5v3.1 | EPSS1.42% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-39379HIGH | Fujitsu Software Infrastructure Manager (ISM) stores sensitive information at the product's maintenance data (ismsnap) in cleartext form. As a result, the password for the proxy server that is configured in ISM may be retrieved. Affected products and versions are as follows: Fujitsu Software Infrastructure Manager Advanced Edition V2.8.0.060, Fujitsu Software Infrastructure Manager Advanced Edition for PRIMEFLEX V2.8.0.060, and Fujitsu Software Infrastructure Manager Essential Edition V2.8.0.060… CWE-312Aug 4, 2023 | CVSS7.5v3.1 | EPSS0.42% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-38433HIGH | fujitsu ip-he950e_firmware Use of Hard-coded CredentialsFujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize or reboot the products, and as a result, terminate the video transmission. Affected products and versions are as follows: IP-HE950E firmware versions V01L001 to V01L053, IP-HE950D firmware versions V01L001 to V01L053, IP-HE900E firmware versions V01L001 to V01L010, IP-HE900D firmware versions V01L001 to V01L004, IP-900E / IP-920E firmware versions V01L… | CVSS7.5v3.1 | EPSS3.72% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2023-38555HIGH | Authentication bypass vulnerability in Fujitsu network devices Si-R series and SR-M series allows a network-adjacent unauthenticated attacker to obtain, change, and/or reset configuration settings of the affected products. Affected products and versions are as follows: Si-R 30B all versions, Si-R 130B all versions, Si-R 90brin all versions, Si-R570B all versions, Si-R370B all versions, Si-R220D all versions, Si-R G100 V02.54 and earlier, Si-R G200 V02.54 and earlier, Si-R G100B V04.12 and earlie… CWE-287Jul 26, 2023 | CVSS8.8v3.1 | EPSS0.372% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-22377HIGH | Improper restriction of XML external entity reference (XXE) vulnerability exists in tsClinical Define.xml Generator all versions (v1.0.0 to v1.4.0) and tsClinical Metadata Desktop Tools Version 1.0.3 to Version 1.1.0. If this vulnerability is exploited, an attacker may obtain an arbitrary file which meets a certain condition by reading a specially crafted XML file. CWE-611Feb 15, 2023 | CVSS7.4v3.1 | EPSS0.677% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-29516CRITICAL | The web console of FUJITSU Network IPCOM series (IPCOM EX2 IN(3200, 3500), IPCOM EX2 LB(1100, 3200, 3500), IPCOM EX2 SC(1100, 3200, 3500), IPCOM EX2 NW(1100, 3200, 3500), IPCOM EX2 DC, IPCOM EX2 DC, IPCOM EX IN(2300, 2500, 2700), IPCOM EX LB(1100, 1300, 2300, 2500, 2700), IPCOM EX SC(1100, 1300, 2300, 2500, 2700), and IPCOM EX NW(1100, 1300, 2300, 2500, 2700)) allows a remote attacker to execute an arbitrary OS command via unspecified vectors. CWE-78May 18, 2022 | CVSS9.8v3.1 | EPSS2.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-10855HIGH | Untrusted search path vulnerability in FENCE-Explorer for Windows V8.4.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. CWE-426Sep 15, 2017 | CVSS7.8v3.0 | EPSS1.06% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |