PatchSiren cyber security CVE debrief
CVE-2025-32412 Fuji Electric CVE debrief
CVE-2025-32412 is a high-severity issue in Fuji Electric Smart Editor. According to the CISA CSAF advisory published on 2025-06-17, versions 1.0.1.0 and earlier are affected by an out-of-bounds read that may allow an attacker to execute arbitrary code. Fuji Electric recommends updating to Smart Editor v1.0.2.0 or later.
- Vendor
- Fuji Electric
- Product
- Smart Editor
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-06-17
- Original CVE updated
- 2025-06-17
- Advisory published
- 2025-06-17
- Advisory updated
- 2025-06-17
Who should care
Fuji Electric Smart Editor users and administrators, especially organizations running version 1.0.1.0 or earlier in operational or industrial environments.
Technical summary
The advisory describes an out-of-bounds read in Fuji Electric Smart Editor. The supplied CVSS vector is CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating local attack conditions with user interaction required and potential high impact if exploited. The affected product is listed as Fuji Electric Smart Editor <=1.0.1.0, and the vendor remediation is to upgrade to v1.0.2.0 or later.
Defensive priority
High. Prioritize patching because the advisory rates the issue HIGH (CVSS 7.8) and states it may allow arbitrary code execution.
Recommended defensive actions
- Inventory all Fuji Electric Smart Editor installations and confirm whether any instance is version 1.0.1.0 or earlier.
- Upgrade affected systems to Smart Editor v1.0.2.0 or later as recommended by Fuji Electric.
- Validate the update in a controlled environment before broad deployment where operational constraints require testing.
- Review access and usage around Smart Editor on systems that handle untrusted files or inputs, and limit use to trusted operators until patched.
- Track the CISA advisory and vendor release notes for any follow-up guidance or revised remediation details.
Evidence notes
The supplied CISA CSAF source for ICSA-25-168-04 states that Fuji Electric Smart Editor <=1.0.1.0 is vulnerable to an out-of-bounds read that may allow arbitrary code execution. The same source includes Fuji Electric's remediation to update to v1.0.2.0 or later. The supplied enrichment also indicates no KEV listing and no known ransomware campaign use.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-32412 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-32412
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-32412 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-32412
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-168-04.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-168-04
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.