panasonic CVE Vulnerabilities & Metrics

Focus on panasonic vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About panasonic Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with panasonic. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total panasonic CVEs: 37
Earliest CVE date: 05 Aug 2008, 20:41 UTC
Latest CVE date: 19 Dec 2023, 01:15 UTC

Latest CVE reference: CVE-2023-6315

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical panasonic CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.44

Max CVSS: 10.0

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 13
4.0-6.9 20
7.0-8.9 6
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS panasonic CVEs

These are the five CVEs with the highest CVSS scores for panasonic, sorted by severity first and recency.

All CVEs for panasonic

CVE-2023-6315 panasonic vulnerability CVSS: 0 19 Dec 2023, 01:15 UTC

Out-of-bouds read vulnerability in FPWin Pro version 7.7.0.0 and all previous versions may allow attackers to execute arbitrary code via a specially crafted project file.

CVE-2023-6314 panasonic vulnerability CVSS: 0 19 Dec 2023, 01:15 UTC

Stack-based buffer overflow in FPWin Pro version 7.7.0.0 and all previous versions may allow attackers to execute arbitrary code via a specially crafted project file.

CVE-2023-3472 panasonic vulnerability CVSS: 0 06 Sep 2023, 05:15 UTC

Use after free vulnerability in Panasonic KW Watcher versions 1.00 through 2.82 may allow attackers to execute arbitrary code.

CVE-2023-3471 panasonic vulnerability CVSS: 0 06 Sep 2023, 05:15 UTC

Buffer overflow vulnerability in Panasonic KW Watcher versions 1.00 through 2.82 may allow attackers to execute arbitrary code.

CVE-2023-28730 panasonic vulnerability CVSS: 0 21 Jul 2023, 07:15 UTC

A memory corruption vulnerability Panasonic Control FPWIN Pro versions 7.6.0.3 and all previous versions may allow arbitrary code execution when opening specially crafted project files.

CVE-2023-28729 panasonic vulnerability CVSS: 0 21 Jul 2023, 07:15 UTC

A type confusion vulnerability in Panasonic Control FPWIN Pro versions 7.6.0.3 and all previous versions may allow arbitrary code execution when opening specially crafted project files.

CVE-2023-28728 panasonic vulnerability CVSS: 0 21 Jul 2023, 07:15 UTC

A stack-based buffer overflow in Panasonic Control FPWIN Pro versions 7.6.0.3 and all previous versions may allow arbitrary code execution when opening specially crafted project files.

CVE-2023-28727 panasonic vulnerability CVSS: 0 31 Mar 2023, 07:15 UTC

Panasonic AiSEG2 versions 2.00J through 2.93A allows adjacent attackers bypass authentication due to mishandling of X-Forwarded-For headers.

CVE-2023-28726 panasonic vulnerability CVSS: 0 31 Mar 2023, 07:15 UTC

Panasonic AiSEG2 versions 2.80F through 2.93A allows remote attackers to execute arbitrary OS commands.

CVE-2022-4621 panasonic vulnerability CVSS: 0 17 Jan 2023, 17:15 UTC

Panasonic Sanyo CCTV Network Cameras versions 1.02-05 and 2.03-0x are vulnerable to CSRFs that can be exploited to allow an attacker to perform changes with administrator level privileges.

CVE-2021-32972 panasonic vulnerability CVSS: 4.3 09 Jul 2021, 11:15 UTC

Panasonic FPWIN Pro, all Versions 7.5.1.1 and prior, allows an attacker to craft a project file specifying a URI that causes the XML parser to access the URI and embed the contents, which may allow the attacker to disclose information that is accessible in the context of the user executing software.

CVE-2021-20623 panasonic vulnerability CVSS: 10.0 05 Feb 2021, 14:15 UTC

Video Insight VMS versions prior to 7.8 allows a remote attacker to execute arbitrary code with the system user privilege by sending a specially crafted request.

CVE-2020-16236 panasonic vulnerability CVSS: 6.8 26 Jan 2021, 18:15 UTC

FPWIN Pro is vulnerable to an out-of-bounds read vulnerability when a user opens a maliciously crafted project file, which may allow an attacker to remotely execute arbitrary code.

CVE-2020-29194 panasonic vulnerability CVSS: 5.0 28 Dec 2020, 07:15 UTC

Panasonic Security System WV-S2231L 4.25 allows a denial of service of the admin control panel (which will require a physical reset to restore administrative control) via Randomnum=99AC8CEC6E845B28&mode=1 in a POST request to the cgi-bin/set_factory URI.

CVE-2020-29193 panasonic vulnerability CVSS: 2.1 28 Dec 2020, 07:15 UTC

Panasonic Security System WV-S2231L 4.25 has an insecure hard-coded password of lkjhgfdsa (which is just the asdf keyboard row in reverse order).

CVE-2020-11716 panasonic vulnerability CVSS: 7.5 20 May 2020, 14:15 UTC

Panasonic P110, Eluga Z1 Pro, Eluga X1, and Eluga X1 Pro devices through 2020-04-10 have Insecure Permissions. NOTE: the vendor states that all affected products are at "End-of-software-support."

CVE-2019-5997 panasonic vulnerability CVSS: 7.5 20 May 2020, 11:15 UTC

Video Insight VMS versions prior to 7.6.1 allow remote attackers to conduct code injection attacks via unspecified vectors.

CVE-2020-11715 panasonic vulnerability CVSS: 7.5 19 May 2020, 17:15 UTC

Panasonic P99 devices through 2020-04-10 have Incorrect Access Control. NOTE: the vendor states that all affected products are at "End-of-software-support."

CVE-2019-15429 panasonic vulnerability CVSS: 7.2 14 Nov 2019, 17:15 UTC

The Panasonic ELUGA_I9 Android device with a build fingerprint of Panasonic/ELUGA_I9/ELUGA_I9:7.0/NRD90M/1501740649:user/release-keys contains a pre-installed app with a package name of com.ovvi.modem app (versionCode=1, versionName=1) that allows unauthorized attacker-controlled at command via a confused deputy attack. This capability can be accessed by any app co-located on the device.

CVE-2019-15378 panasonic vulnerability CVSS: 2.1 14 Nov 2019, 17:15 UTC

The Panasonic Eluga Ray 600 Android device with a build fingerprint of Panasonic/ELUGA_Ray_600/ELUGA_Ray_600:8.1.0/O11019/1532692680:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.

CVE-2019-15376 panasonic vulnerability CVSS: 2.1 14 Nov 2019, 17:15 UTC

The Panasonic Eluga Ray 530 Android device with a build fingerprint of Panasonic/ELUGA_Ray_530/ELUGA_Ray_530:8.1.0/O11019/1531828974:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.

CVE-2019-5996 panasonic vulnerability CVSS: 6.5 12 Sep 2019, 17:15 UTC

SQL injection vulnerability in the Video Insight VMS 7.3.2.5 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2019-6532 panasonic vulnerability CVSS: 6.8 07 Jun 2019, 14:29 UTC

Panasonic FPWIN Pro version 7.3.0.0 and prior allows attacker-created project files to be loaded by an authenticated user triggering incompatible type errors because the resource does not have expected properties. This may lead to remote code execution.

CVE-2019-6530 panasonic vulnerability CVSS: 6.8 07 Jun 2019, 14:29 UTC

Panasonic FPWIN Pro version 7.3.0.0 and prior allows attacker-created project files to be loaded by an authenticated user causing heap-based buffer overflows, which may lead to remote code execution.

CVE-2018-16183 panasonic vulnerability CVSS: 6.8 09 Jan 2019, 23:29 UTC

An unquoted search path vulnerability in some pre-installed applications on Panasonic PC run on Windows 7 (32bit), Windows 7 (64bit), Windows 8 (64bit), Windows 8.1 (64bit), Windows 10 (64bit) delivered in or later than October 2009 allow local users to gain privileges via a Trojan horse executable file and execute arbitrary code with eleveted privileges.

CVE-2018-0678 panasonic vulnerability CVSS: 5.2 09 Jan 2019, 23:29 UTC

Buffer overflow in BN-SDWBP3 firmware version 1.0.9 and earlier allows an attacker on the same network segment to execute arbitrary code via unspecified vectors.

CVE-2018-0677 panasonic vulnerability CVSS: 7.7 09 Jan 2019, 23:29 UTC

BN-SDWBP3 firmware version 1.0.9 and earlier allows attacker with administrator rights on the same network segment to execute arbitrary OS commands via unspecified vectors.

CVE-2018-0676 panasonic vulnerability CVSS: 5.8 09 Jan 2019, 23:29 UTC

BN-SDWBP3 firmware version 1.0.9 and earlier allows an attacker on the same network segment to bypass authentication to access to the management screen and execute an arbitrary command via unspecified vectors.

CVE-2017-2133 panasonic vulnerability CVSS: 6.5 20 Oct 2017, 11:29 UTC

SQL injection vulnerability in Panasonic KX-HJB1000 Home unit devices with firmware GHX1YG 14.50 or HJB1000_4.47 allows authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2017-2132 panasonic vulnerability CVSS: 6.4 20 Oct 2017, 11:29 UTC

Panasonic KX-HJB1000 Home unit devices with firmware GHX1YG 14.50 or HJB1000_4.47 allow an attacker to delete arbitrary files in a specific directory via unspecified vectors.

CVE-2017-2131 panasonic vulnerability CVSS: 5.0 20 Oct 2017, 11:29 UTC

Panasonic KX-HJB1000 Home unit devices with firmware GHX1YG 14.50 or HJB1000_4.47 allow an attacker to bypass access restrictions to view the configuration menu via unspecified vectors.

CVE-2017-5151 panasonic vulnerability CVSS: 7.5 13 Feb 2017, 21:59 UTC

An issue was discovered in VideoInsight Web Client Version 6.3.5.11 and previous versions. A SQL Injection vulnerability has been identified, which may allow remote code execution.

CVE-2016-4499 panasonic vulnerability CVSS: 4.4 12 May 2016, 01:59 UTC

Heap-based buffer overflow in Panasonic FPWIN Pro 5.x through 7.x before 7.130 allows local users to cause a denial of service (application crash) via unspecified vectors.

CVE-2016-4498 panasonic vulnerability CVSS: 6.8 12 May 2016, 01:59 UTC

Panasonic FPWIN Pro 5.x through 7.x before 7.130 accesses an uninitialized pointer, which allows local users to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVE-2016-4497 panasonic vulnerability CVSS: 6.8 12 May 2016, 01:59 UTC

Panasonic FPWIN Pro 5.x through 7.x before 7.130 allows local users to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."

CVE-2016-4496 panasonic vulnerability CVSS: 4.4 12 May 2016, 01:59 UTC

Panasonic FPWIN Pro 5.x through 7.x before 7.130 allows local users to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by triggering a crafted index value, as demonstrated by an integer overflow.

CVE-2014-9596 panasonic vulnerability CVSS: 4.3 15 Jan 2015, 23:59 UTC

Panasonic Arbitrator Back-End Server (BES) MK 2.0 VPU before 9.3.1 build 4.08.003.0, when USB Wi-Fi or Direct LAN is enabled, and MK 3.0 VPU before 9.3.1 build 5.06.000.0, when Embedded Wi-Fi or Direct LAN is enabled, does not use encryption, which allows remote attackers to obtain sensitive information by sniffing the network for client-server traffic, as demonstrated by Active Directory credential information.

CVE-2014-8756 panasonic vulnerability CVSS: 6.8 17 Oct 2014, 15:55 UTC

The NcrCtl4.NcrNet.1 control in Panasonic Network Camera Recorder before 4.04R03 allows remote attackers to execute arbitrary code via a crafted GetVOLHeader method call, which writes null bytes to an arbitrary address.

CVE-2014-8755 panasonic vulnerability CVSS: 6.8 17 Oct 2014, 15:55 UTC

Panasonic Network Camera View 3 and 4 allows remote attackers to execute arbitrary code via a crafted page, which triggers an invalid pointer dereference, related to "the ability to nullify an arbitrary address in memory."

CVE-2008-3482 panasonic vulnerability CVSS: 4.3 05 Aug 2008, 20:41 UTC

Cross-site scripting (XSS) vulnerability in the error page feature in Panasonic Network Camera BL-C111, BL-C131, BB-HCM511, BB-HCM531, BB-HCM580, BB-HCM581, BB-HCM527, and BB-HCM515 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.