Use-After Free Vulnerability in CX-Programmer Software from OMRON
CVE-2022-43508

7.8HIGH

Key Information:

Vendor
CVE Published:
7 December 2022

What is CVE-2022-43508?

A use-after free vulnerability has been identified in CX-Programmer version 9.77 and earlier. This vulnerability occurs when a user opens a specially crafted CXP file, potentially allowing attackers to execute arbitrary code or disclose sensitive information, posing significant security risks for users. It's crucial for organizations utilizing this software to assess exposure and apply necessary mitigations to safeguard their systems.

Affected Version(s)

CX-Programmer v.9.77 and earlier

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.