PatchSiren cyber security CVE debrief
CVE-2024-11801 Fuji Electric CVE debrief
A high-severity arbitrary code execution vulnerability in Fuji Electric Tellus Lite V-Simulator 5 (VS5Sim) allows remote attackers to execute code in the context of the current process when a user opens a malicious V8 file. The flaw stems from improper validation of user-supplied data during V8 file parsing, resulting in an out-of-bounds write. This vulnerability requires user interaction and has a CVSS 3.1 score of 7.8. Fuji Electric has addressed this by replacing V-SFT Ver5 with V-SFT Ver6 in newer TELLUS Lite versions, with VS6Sim incorporating input screening to block malicious files targeting this and related vulnerabilities (CVE-2024-11799, CVE-2024-11800).
- Vendor
- Fuji Electric
- Product
- Tellus Lite
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-12-03
- Original CVE updated
- 2025-07-29
- Advisory published
- 2024-12-03
- Advisory updated
- 2025-07-29
Who should care
Organizations operating Fuji Electric Tellus Lite HMI/SCADA systems, particularly in manufacturing, energy, and critical infrastructure sectors. Security teams responsible for OT/ICS asset protection, patch management personnel, and operators of industrial workstations running V-Simulator components.
Technical summary
The vulnerability exists in the V-Simulator 5 (VS5Sim) component's parsing of V8 files. Insufficient validation of user-supplied data allows a write past the end of an allocated buffer, enabling arbitrary code execution in the context of the current process. Exploitation requires user interaction—specifically, opening a malicious V8 file or visiting a malicious page that triggers file handling. Fuji Electric's remediation replaces the vulnerable V-SFT Ver5 with V-SFT Ver6; VS6Sim includes input validation to screen incoming data and prevent exploitation of this vulnerability and related flaws (CVE-2024-11799, CVE-2024-11800).
Defensive priority
HIGH
Recommended defensive actions
- Upgrade to TELLUS Lite V4.0.22.0 or later, which replaces V-SFT Ver5 with V-SFT Ver6 and includes VS6Sim with malicious file screening
- If running Tellus Lite 4.0.20.0, apply vendor-provided mitigations and monitor for updates
- Implement application whitelisting to restrict execution of unapproved V8 files
- Train users to avoid opening V8 files from untrusted sources
- Deploy endpoint protection with behavioral monitoring for industrial control system workstations
- Segment OT networks to limit lateral movement if compromise occurs
- Review and apply CISA ICS recommended practices for defense-in-depth
Evidence notes
Vulnerability disclosed via CISA ICS advisory ICSA-24-338-06 on 2024-12-03. Advisory updated 2025-07-29 to note TELLUS V4.0.22.0 release addressing related CVEs. Affected version: Tellus Lite 4.0.20.0. CVSS 3.1 vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-11801 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-11801
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-11801 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-11801
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-338-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-06
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.