Heap-Based Buffer Overflow in Omron CX-One Vulnerable Products
CVE-2018-8834

7.8HIGH

Key Information:

Vendor

Ics-cert

Vendor
CVE Published:
17 April 2018

What is CVE-2018-8834?

The vulnerability in Omron CX-One allows attackers to exploit malformed project files, leading to possible heap-based buffer overflows. This could allow for arbitrary code execution or system manipulation, affecting multiple applications including CX-FLnet, CX-Protocol, CX-Programmer, CX-Server, Network Configurator, and Switch Box Utility in versions prior to specified thresholds. Such vulnerabilities pose significant risks and underscore the necessity for vigilant software updates and mitigation strategies.

Affected Version(s)

Omron CX-One The following versions of CX-One are affected: CX-One Versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-Protocol versions 1.992 and prior, CX-Programmer versions 9.65 and prior, CX-Server versions 5.0.22 and prior, Network Configurator versions 3.63 and prior, and Switch Box Utility versions 1.68 and prior.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.