PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-11801 Fuji Electric CVE debrief

A high-severity arbitrary code execution vulnerability in Fuji Electric Tellus Lite V-Simulator 5 (VS5Sim) allows remote attackers to execute code in the context of the current process when a user opens a malicious V8 file. The flaw stems from improper validation of user-supplied data during V8 file parsing, resulting in an out-of-bounds write. This vulnerability requires user interaction and has a CVSS 3.1 score of 7.8. Fuji Electric has addressed this by replacing V-SFT Ver5 with V-SFT Ver6 in newer TELLUS Lite versions, with VS6Sim incorporating input screening to block malicious files targeting this and related vulnerabilities (CVE-2024-11799, CVE-2024-11800).

Vendor
Fuji Electric
Product
Tellus Lite
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-12-03
Original CVE updated
2025-07-29
Advisory published
2024-12-03
Advisory updated
2025-07-29

Who should care

Organizations operating Fuji Electric Tellus Lite HMI/SCADA systems, particularly in manufacturing, energy, and critical infrastructure sectors. Security teams responsible for OT/ICS asset protection, patch management personnel, and operators of industrial workstations running V-Simulator components.

Technical summary

The vulnerability exists in the V-Simulator 5 (VS5Sim) component's parsing of V8 files. Insufficient validation of user-supplied data allows a write past the end of an allocated buffer, enabling arbitrary code execution in the context of the current process. Exploitation requires user interaction—specifically, opening a malicious V8 file or visiting a malicious page that triggers file handling. Fuji Electric's remediation replaces the vulnerable V-SFT Ver5 with V-SFT Ver6; VS6Sim includes input validation to screen incoming data and prevent exploitation of this vulnerability and related flaws (CVE-2024-11799, CVE-2024-11800).

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade to TELLUS Lite V4.0.22.0 or later, which replaces V-SFT Ver5 with V-SFT Ver6 and includes VS6Sim with malicious file screening
  • If running Tellus Lite 4.0.20.0, apply vendor-provided mitigations and monitor for updates
  • Implement application whitelisting to restrict execution of unapproved V8 files
  • Train users to avoid opening V8 files from untrusted sources
  • Deploy endpoint protection with behavioral monitoring for industrial control system workstations
  • Segment OT networks to limit lateral movement if compromise occurs
  • Review and apply CISA ICS recommended practices for defense-in-depth

Evidence notes

Vulnerability disclosed via CISA ICS advisory ICSA-24-338-06 on 2024-12-03. Advisory updated 2025-07-29 to note TELLUS V4.0.22.0 release addressing related CVEs. Affected version: Tellus Lite 4.0.20.0. CVSS 3.1 vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-11801 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-11801

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-11801 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-11801

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-338-06.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-06

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.