Impact
The kernel driver installed by Fuji Tellus grants all users full read and write permissions on the system, enabling any user to read protected data or modify critical files. This creates a high‑risk scenario where compromised or legitimate local users could exfiltrate data, inject malicious code, or alter system configurations. The weakness reflects improper access control (CWE‑749).
Affected Systems
Fuji Electric Tellus is the sole affected product; all versions that install the driver are impacted, as no version restrictions are noted in the CNA data.
Risk and Exploitability
With a CVSS score of 7.8, the vulnerability poses significant risk for systems that have installed the Tellus driver. The EPSS score is not available, but the lack of a KEV listing suggests limited current exploitation data; however, the attack vector is inferred to be local, requiring the attacker to be on‑premises to install the driver and exploit the unrestricted permissions. Absent a patch, the risk remains high for any user with local access.
OpenCVE Enrichment