Impact
The vulnerability exists in Fujitsu Linux openFT and Fujitsu Oracle Solaris openFT before version 12.1D00. It permits attackers without authentication to execute arbitrary code, resulting in full system compromise. The weakness is a code injection flaw (CWE‑94).
Affected Systems
Fujitsu Linux openFT and Fujitsu Oracle Solaris openFT products, all releases prior to 12.1D00. These include the standard Linux distribution and the Oracle Solaris implementation of openFT.
Risk and Exploitability
The CVSS score of 9.3 marks this as a critical vulnerability with high potential impact. EPSS Score of < 1% indicates a very low exploitation probability. The likely attack vector is remote network access to the openFT service, and an attacker can trigger arbitrary code execution by crafting a malicious request. Owing to its pre‑authentication nature, the vulnerability can be exploited without any user interaction, making it a top‑priority for remediation.
OpenCVE Enrichment