Memory Reference Flaw in CX-One by OMRON
CVE-2018-18989

7.8HIGH

Key Information:

Vendor

Omron

Vendor
CVE Published:
4 December 2018

What is CVE-2018-18989?

In CX-One applications, including CX-Programmer and CX-Server, a vulnerability exists related to the improper management of memory. When processing project files, the application does not adequately check whether it is referencing memory that has already been freed. This oversight allows an attacker to craft a malicious project file that, when processed, can lead to the execution of arbitrary code with the privileges of the affected application. The exploitation of this vulnerability poses significant risks in environments where CX-One software is utilized.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

CX-One (CX-Programmer and CX-Server) CX-One Versions 4.42 and prior (CX-Programmer Versions 9.66 and prior and CX-Server Versions 5.0.23 and prior)

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.