CVE-2009-0271
CVE-2009-0271 is a medium-severity vulnerability in Fujitsu Systemcastwizard Lite with a CVSS 2.0 base score of 5.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-22.
Key facts
- Severity: Medium (CVSS 2.0 base score 5.0)
- EPSS exploit prediction: 2% (75th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-22
- Affected product: Fujitsu Systemcastwizard Lite
- Published:
- Last modified:
Description
Directory traversal vulnerability in the TFTP service in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors.
Frequently asked questions
- What is CVE-2009-0271?
- Directory traversal vulnerability in the TFTP service in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors.
- How severe is CVE-2009-0271?
- CVE-2009-0271 has a CVSS 2.0 base score of 5.0, rated medium severity.
- Is CVE-2009-0271 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (75th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2009-0271?
- CVE-2009-0271 primarily affects Fujitsu Systemcastwizard Lite. In total, 6 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2009-0271?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2009-0271 published?
- CVE-2009-0271 was published on 2009-01-26 and last updated on 2026-06-16.
References
- http://osvdb.org/51487
- http://secunia.com/advisories/33594
- http://www.fujitsu.com/global/services/computing/server/primequest/products/os/windows-server-2008-2.html
- http://www.securityfocus.com/bid/33344
- http://www.vupen.com/english/advisories/2009/0176
Affected products (6)
- cpe:2.3:a:fujitsu:systemcastwizard_lite:1.7:*:*:*:*:*:*:*
- cpe:2.3:a:fujitsu:systemcastwizard_lite:1.8:*:*:*:*:*:*:*
- cpe:2.3:a:fujitsu:systemcastwizard_lite:1.8a:*:*:*:*:*:*:*
- cpe:2.3:a:fujitsu:systemcastwizard_lite:1.9:*:*:*:*:*:*:*
- cpe:2.3:a:fujitsu:systemcastwizard_lite:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:fujitsu:systemcastwizard_lite:2.0a:*:*:*:*:*:*:*
More vulnerabilities in Fujitsu Systemcastwizard Lite
- CVE-2009-0270 — Critical (CVSS 10.0): Stack-based buffer overflow in PXEService.exe in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier allows…
- CVE-2009-0264 — Critical (CVSS 10.0): Buffer overflow in the Registry Setting Tool in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier has unknown…
All CVEs affecting Fujitsu Systemcastwizard Lite →
Other CWE-22 (Path Traversal) vulnerabilities
- CVE-2026-80155 — Critical (CVSS 10.0): Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of…
- CVE-2026-70200 — Critical (CVSS 10.0): Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an…
- CVE-2026-85706 — Critical (CVSS 10.0): GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and…
- CVE-2026-76606 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.
- CVE-2026-18051 — Critical (CVSS 10.0): The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache…
- CVE-2026-74764 — Critical (CVSS 10.0): Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a…