CVE-2018-18989: Use After Free
Published Dec 4, 2018
·Updated
In CX-One Versions 4.42 and prior (CX-Programmer Versions 9.66 and prior and CX-Server Versions 5.0.23 and prior), when processing project files, the application fails to check if it is referencing freed memory. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.
Affected Software
3 affected components
Omron CX-One<=4.42
Omron CX-Programmer<=9.66
Omron CX-Server<=5.0.23
Event History
Dec 4, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-18989.
2
What is the severity of CVE-2018-18989?
The severity of CVE-2018-18989 is high with a CVSS score of 7.8.
3
Which software versions are affected by CVE-2018-18989?
CX-One versions up to and including 4.42, CX-Programmer versions up to and including 9.66, and CX-Server versions up to and including 5.0.23 are affected by CVE-2018-18989.
4
What is the CWE ID for CVE-2018-18989?
The CWE ID for CVE-2018-18989 is CWE-416.
5
How can CVE-2018-18989 be exploited?
CVE-2018-18989 can be exploited by using a specially crafted project file to execute code.