← Vulnerability feed

Vulnerability record · CVE-2019-18240 · published 13 November 2019

CVE-2019-18240: Fujielectric v-server heap-based buffer overflow vulnerability

FFujielectric · V Server

In Fuji Electric V-Server 4.0.6 and prior, several heap-based buffer overflows have been identified, which may allow an attacker to remotely execute arbitrary code.

9.8 CVSS 3.1 Critical EPSS 14% · top 3.5% CWE-122 · Heap-based buffer overflowCWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score, v2 7.5
14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In Fuji Electric V-Server 4.0.6 and prior, several heap-based buffer overflows have been identified, which may allow an attacker to remotely execute arbitrary code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.us-cert.gov/ics/advisories/icsa-19-311-02 Third Party AdvisoryUS Government Resource
https://www.us-cert.gov/ics/advisories/icsa-19-311-02 Third Party AdvisoryUS Government Resource

Track CVE-2019-18240 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-3947Fujielectric v-server insufficiently protected credentials vulnerabilityFuji Electric V-Server before 6.0.33.0 stores database credentials in project files as plaintext. An attacker that can gain access to the project fil…EPSS 1.6%7.8CVE-2023-47584Fujielectric v-server out-of-bounds write vulnerabilityOut-of-bounds write vulnerability exists in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a user opens a specially craft…EPSS 0.27%7.8CVE-2023-47585Fujielectric v-server out-of-bounds read vulnerabilityOut-of-bounds read vulnerability exists in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a user opens a specially crafte…EPSS 0.27%7.8CVE-2023-47586Fujielectric v-server out-of-bounds write vulnerabilityMultiple heap-based buffer overflow vulnerabilities exist in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a user opens …EPSS 0.29%7.8CVE-2023-31239Fujielectric v-server out-of-bounds read vulnerabilityStack-based buffer overflow vulnerability in V-Server v4.0.15.0 and V-Server Lite v4.0.15.0 and earlier allows an attacker to execute arbitrary code …EPSS 0.27%7.8CVE-2022-41645Fujielectric v-server out-of-bounds read vulnerabilityOut-of-bounds read vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitrary code by…EPSS 0.23%7.8CVE-2022-47317Fujielectric v-server out-of-bounds write vulnerabilityOut-of-bounds write vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitrary code b…EPSS 0.23%7.8CVE-2022-47908Fujielectric v-server out-of-bounds write vulnerabilityStack-based buffer overflow vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitrar…EPSS 0.25%

Source: NIST National Vulnerability Database (record CVE-2019-18240), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.