Vulnerabilities > Fanuc

DATE CVE VULNERABILITY TITLE RISK
2023-06-07 CVE-2023-1864 Path Traversal vulnerability in Fanuc Roboguide Handlingpro Firmware
FANUC ROBOGUIDE-HandlingPRO Versions 9 Rev.ZD and prior is vulnerable to a path traversal, which could allow an attacker to remotely read files on the system running the affected software.
network
low complexity
fanuc CWE-22
7.5
2022-04-20 CVE-2021-38483 Incorrect Permission Assignment for Critical Resource vulnerability in Fanuc Roboguide 9.40083.00.05
The affected product is vulnerable to misconfigured binaries, allowing users on the target PC with SYSTEM level privileges access to overwrite the binary and modify files to gain privilege escalation.
local
high complexity
fanuc CWE-732
5.7
2022-04-20 CVE-2021-43933 Resource Exhaustion vulnerability in Fanuc Roboguide 9.40083.00.05
The affected product is vulnerable to a network-based attack by threat actors sending unimpeded requests to the receiving server, which could cause a denial-of-service condition due to lack of heap memory resources.
network
high complexity
fanuc CWE-400
5.9
2022-04-20 CVE-2021-43986 Incorrect Default Permissions vulnerability in Fanuc Roboguide 9.40083.00.05
The setup program for the affected product configures its files and folders with full access, which may allow unauthorized users permission to replace original binaries and achieve privilege escalation.
local
high complexity
fanuc CWE-276
7.0
2022-04-20 CVE-2021-43988 Unspecified vulnerability in Fanuc Roboguide 9.40083.00.05
The affected product is vulnerable to a network-based attack by threat actors utilizing crafted naming conventions of files to gain unauthorized access rights.
network
high complexity
fanuc
5.9
2022-04-20 CVE-2021-43990 XXE vulnerability in Fanuc Roboguide 9.40083.00.05
The affected product is vulnerable to a network-based attack by threat actors supplying a crafted, malicious XML payload designed to trigger an external entity reference call.
network
high complexity
fanuc CWE-611
5.3
2022-01-10 CVE-2021-32996 Incorrect Conversion between Numeric Types vulnerability in Fanuc products
The FANUC R-30iA and R-30iB series controllers are vulnerable to integer coercion errors, which cause the device to crash.
network
low complexity
fanuc CWE-681
7.8
2022-01-10 CVE-2021-32998 Out-of-bounds Write vulnerability in Fanuc products
The FANUC R-30iA and R-30iB series controllers are vulnerable to an out-of-bounds write, which may allow an attacker to remotely execute arbitrary code.
network
fanuc CWE-787
8.8
2020-08-03 CVE-2020-12739 Improper Input Validation vulnerability in Fanuc products
A denial-of-service vulnerability in the Fanuc i Series CNC (0i-MD and 0i Mate-MD) could allow an unauthenticated, remote attacker to cause an affected CNC to become inaccessible to other devices.
network
low complexity
fanuc CWE-20
5.0