PatchSiren cyber security CVE debrief
CVE-2024-11803 Fuji Electric CVE debrief
A high-severity memory corruption vulnerability in Fuji Electric Tellus Lite V-Simulator enables remote code execution through malicious V8 files. The flaw stems from insufficient input validation during V8 file parsing in V-Simulator 5, allowing an out-of-bounds write that can be exploited to execute arbitrary code within the current process context. User interaction is required—targets must open a crafted file or visit a malicious page. The vulnerability was disclosed on December 3, 2024, with an updated advisory published July 29, 2025, confirming that Fuji Electric released TELLUS V4.0.22.0 in May 2025 to address this issue by replacing V-Simulator Ver5 with Ver6.
- Vendor
- Fuji Electric
- Product
- Tellus Lite
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-12-03
- Original CVE updated
- 2025-07-29
- Advisory published
- 2024-12-03
- Advisory updated
- 2025-07-29
Who should care
Industrial control system operators, OT security teams, and organizations using Fuji Electric Tellus Lite for HMI/SCADA applications should prioritize patching. The vulnerability poses significant risk to manufacturing, energy, and critical infrastructure environments where Tellus Lite is deployed for process visualization and control.
Technical summary
The vulnerability exists in the V-Simulator 5 component's V8 file parser. Insufficient validation of user-supplied data allows a write beyond allocated buffer boundaries, corrupting memory and enabling code execution in the context of the current process. The attack vector requires local access with user interaction (opening a malicious V8 file), but the resulting impact is high—complete confidentiality, integrity, and availability compromise of the process. The fix involves migrating to V-Simulator Ver6 in TELLUS V4.0.22.0, which properly validates V8 file data structures.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade to Fuji Electric TELLUS V4.0.22.0 or later, which replaces V-Simulator Ver5 with Ver6 and resolves this vulnerability
- If immediate patching is not feasible, restrict user permissions to prevent execution of untrusted V8 files and implement application whitelisting
- Train operators to avoid opening V8 files from untrusted sources and to verify file origins before loading into V-Simulator
- Monitor for suspicious V-Simulator process behavior or unexpected network connections from the application
- Apply defense-in-depth controls including network segmentation for systems running Tellus Lite to limit lateral movement if compromise occurs
Evidence notes
Vulnerability disclosed via CISA ICS advisory ICSA-24-338-06. Advisory updated July 29, 2025 to confirm patch availability. CVSS 3.1 score 7.8 (HIGH). No known exploitation in the wild or ransomware campaign use documented.
Official resources
-
CVE-2024-11803 CVE record
CVE.org
-
CVE-2024-11803 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2024-12-03