Buffer Overflow Vulnerability in Omron CX-One and Sysmac Studio Products
CVE-2024-31413

5.9MEDIUM

What is CVE-2024-31413?

A buffer overflow vulnerability affects both CX-One and Sysmac Studio products from Omron, specifically versions that were either installed with a DVD version prior to the specified updates or were updated through their auto-update features before January 2024. The vulnerability can be exploited when a user opens a specially crafted project file, potentially allowing for arbitrary code execution, posing significant security risks to user systems.

Affected Version(s)

CX-One CX-One CXONE-AL[][]D-V4 The version which was installed with a DVD ver. 4.61.1 or lower

CX-One CX-One CXONE-AL[][]D-V4 and was updated through CX-One V4 auto update in January 2024 or prior

Sysmac Studio SYSMAC-SE2[][][] The version which was installed with a DVD ver. 1.56 or lower

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.