Fujitsu's vulnerability footprint spans a substantial portfolio of enterprise servers, storage systems, and infrastructure products deployed across high-value computing environments, establishing the vendor as a prominent presence in the vulnerability landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a notable tendency to acquire public exploit code, particularly across its M10, M12, and related firmware-driven platforms. The exposure recurs through weakness classes including memory-buffer overflows, path-traversal flaws, and cross-site scripting, alongside a baseline of uncategorized findings typical of firmware and lower-level components where precise CWE attribution remains incomplete. Defenders should prioritize Fujitsu advisories affecting internet-reachable or administratively exposed systems and track firmware release cycles closely, as exploitation tooling may emerge for serious flaws in this product class. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fujitsu over time
Signals from CVEs in this vendor scope (79 CVEs).
79 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-2251CRITICAL Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: p | Jul 20, 2013 | 9.8 | 99 | YES | YES |
CVE-2013-2566MEDIUM The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via s | Mar 15, 2013 | 5.9 | 80 | NO | YES |
CVE-2019-6111MEDIUM An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the s | Jan 31, 2019 | 5.9 | 67 | NO | YES |
CVE-2021-23840HIGH Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable | Feb 16, 2021 | 7.5 | 53 | NO | NO |
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remot | Apr 1, 2015 | 3.7 | 52 | NO | NO |
CVE-2016-8610HIGH A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection | Nov 13, 2017 | 7.5 | 39 | NO | NO |
CVE-2018-1000007CRITICAL libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom headers in its HTTP requests, libcurl will send that set of heade | Jan 24, 2018 | 9.8 | 37 | NO | NO |
CVE-2018-16156HIGH In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes unauthenticated messages received over the FjtwMkic_Fjicube_3 | May 17, 2019 | 7.8 | 36 | NO | YES |
CVE-2023-38433HIGH Fujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize or reboot the products, and as a r | Jul 26, 2023 | 7.5 | 31 | NO | YES |
CVE-2022-29516CRITICAL The web console of FUJITSU Network IPCOM series (IPCOM EX2 IN(3200, 3500), IPCOM EX2 LB(1100, 3200, 3500), IPCOM EX2 SC(1100, 3200, 3500), IPCOM EX2 NW(1100, 3200, 3500), IPCOM EX2 | May 18, 2022 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (79 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fujitsu.
Media articles that mention a CVE ID that affects a product developed by Fujitsu — matched by CVE ID, not by vendor name.