First published: Tue Dec 04 2018(Updated: )
In CX-One Versions 4.42 and prior (CX-Programmer Versions 9.66 and prior and CX-Server Versions 5.0.23 and prior), when processing project files, the application fails to check if it is referencing freed memory. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Omron CX-One | <=4.42 | |
Omron CX-Programmer | <=9.66 | |
Omron Cx-server | <=5.0.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-18989.
The severity of CVE-2018-18989 is high with a CVSS score of 7.8.
CX-One versions up to and including 4.42, CX-Programmer versions up to and including 9.66, and CX-Server versions up to and including 5.0.23 are affected by CVE-2018-18989.
The CWE ID for CVE-2018-18989 is CWE-416.
CVE-2018-18989 can be exploited by using a specially crafted project file to execute code.