Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Fujitsu

First CVE: Aug 1, 1999Active for: 27 yearsTotal CVEs: 79
48.5
VTI Score
High

Fujitsu's vulnerability footprint spans a substantial portfolio of enterprise servers, storage systems, and infrastructure products deployed across high-value computing environments, establishing the vendor as a prominent presence in the vulnerability landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a notable tendency to acquire public exploit code, particularly across its M10, M12, and related firmware-driven platforms. The exposure recurs through weakness classes including memory-buffer overflows, path-traversal flaws, and cross-site scripting, alongside a baseline of uncategorized findings typical of firmware and lower-level components where precise CWE attribution remains incomplete. Defenders should prioritize Fujitsu advisories affecting internet-reachable or administratively exposed systems and track firmware release cycles closely, as exploitation tooling may emerge for serious flaws in this product class. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
79
Total CVEs
More Total CVEs than 99% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
1.3%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Fujitsu over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 1, 1999
26 years ago
Most Recent CVE
Sep 4, 2024
688 days ago

Products(646 total)

Top CVEs

Signals from CVEs in this vendor scope (79 CVEs).

79 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-2251CRITICAL
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: p
Jul 20, 20139.899YESYES
CVE-2013-2566MEDIUM
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via s
Mar 15, 20135.980NOYES
CVE-2019-6111MEDIUM
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the s
Jan 31, 20195.967NOYES
CVE-2021-23840HIGH
Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable
Feb 16, 20217.553NONO
CVE-2015-2808LOW
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remot
Apr 1, 20153.752NONO
CVE-2016-8610HIGH
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection
Nov 13, 20177.539NONO
CVE-2018-1000007CRITICAL
libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom headers in its HTTP requests, libcurl will send that set of heade
Jan 24, 20189.837NONO
CVE-2018-16156HIGH
In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes unauthenticated messages received over the FjtwMkic_Fjicube_3
May 17, 20197.836NOYES
CVE-2023-38433HIGH
Fujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize or reboot the products, and as a r
Jul 26, 20237.531NOYES
CVE-2022-29516CRITICAL
The web console of FUJITSU Network IPCOM series (IPCOM EX2 IN(3200, 3500), IPCOM EX2 LB(1100, 3200, 3500), IPCOM EX2 SC(1100, 3200, 3500), IPCOM EX2 NW(1100, 3200, 3500), IPCOM EX2
May 18, 20229.831NONO
View all 79 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products79 CVEs
47%
35%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local10 (12.7%)
Network32 (40.5%)
Unknown33 (41.8%)
Physical2 (2.5%)
Adjacent Network2 (2.5%)
Attack Complexity
Low35 (44.3%)
High11 (13.9%)
Unknown33 (41.8%)
User Interaction
None38 (48.1%)
Unknown33 (41.8%)
Required8 (10.1%)
Privileges Required
Low10 (12.7%)
High0 (0.0%)
None36 (45.6%)
Unknown33 (41.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (79 CVEs).

CISA KEV
1 CVE
1.3% of CVEs· 99th percentile
Metasploit
2 CVEs
2.5% of CVEs· 97th percentile
Nuclei
2 CVEs
2.5% of CVEs· 95th percentile
ExploitDB
6 CVEs
7.6% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Fujitsu.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Fujitsu — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Fujitsu's Products

View all 8 CNAs →

Top CWEs