PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-32412 Fuji Electric CVE debrief

CVE-2025-32412 is a high-severity issue in Fuji Electric Smart Editor. According to the CISA CSAF advisory published on 2025-06-17, versions 1.0.1.0 and earlier are affected by an out-of-bounds read that may allow an attacker to execute arbitrary code. Fuji Electric recommends updating to Smart Editor v1.0.2.0 or later.

Vendor
Fuji Electric
Product
Smart Editor
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-06-17
Original CVE updated
2025-06-17
Advisory published
2025-06-17
Advisory updated
2025-06-17

Who should care

Fuji Electric Smart Editor users and administrators, especially organizations running version 1.0.1.0 or earlier in operational or industrial environments.

Technical summary

The advisory describes an out-of-bounds read in Fuji Electric Smart Editor. The supplied CVSS vector is CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating local attack conditions with user interaction required and potential high impact if exploited. The affected product is listed as Fuji Electric Smart Editor <=1.0.1.0, and the vendor remediation is to upgrade to v1.0.2.0 or later.

Defensive priority

High. Prioritize patching because the advisory rates the issue HIGH (CVSS 7.8) and states it may allow arbitrary code execution.

Recommended defensive actions

  • Inventory all Fuji Electric Smart Editor installations and confirm whether any instance is version 1.0.1.0 or earlier.
  • Upgrade affected systems to Smart Editor v1.0.2.0 or later as recommended by Fuji Electric.
  • Validate the update in a controlled environment before broad deployment where operational constraints require testing.
  • Review access and usage around Smart Editor on systems that handle untrusted files or inputs, and limit use to trusted operators until patched.
  • Track the CISA advisory and vendor release notes for any follow-up guidance or revised remediation details.

Evidence notes

The supplied CISA CSAF source for ICSA-25-168-04 states that Fuji Electric Smart Editor <=1.0.1.0 is vulnerable to an out-of-bounds read that may allow arbitrary code execution. The same source includes Fuji Electric's remediation to update to v1.0.2.0 or later. The supplied enrichment also indicates no KEV listing and no known ransomware campaign use.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-32412 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-32412

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-32412 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-32412

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-168-04.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-168-04

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.