Fuji Electric Monitouch V-SFT
Fuji Electric Monitouch V-SFT contains multiple buffer overflow and memory corruption vulnerabilities (CWE-121, CWE-122) and improper privilege management (CWE-269) in versions prior to 5.4.43.0. These flaws allow remote attackers without credentials to read sensitive information, modify settings, or cause denial of service by exploiting weak input validation in the HMI communication protocol. The vulnerability affects energy sector operators relying on V-SFT for SCADA visualization and process management.
- Network connectivity to Monitouch V-SFT (typically port 21866 or similar HMI communication port)
- No authentication required
- Ability to craft and send network packets
Patching may require device reboot — plan for process interruption
/api/v1/advisories/4778363a-1f03-407c-b10a-1d0ce7fdec14Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.