CVE-2018-19011: Code Injection
Published Jan 22, 2019
·Updated
CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file. An attacker could exploit this to execute code under the privileges of the application.
Affected Software
1 affected component
Omron CX-Supervisor<=3.42
Event History
Jan 22, 2019
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-19011.
2
What is the severity level of CVE-2018-19011?
CVE-2018-19011 has a severity level of high.
3
What is the affected software for CVE-2018-19011?
The affected software for CVE-2018-19011 is CX-Supervisor versions 3.42 and prior.
4
How can an attacker exploit CVE-2018-19011?
An attacker can exploit CVE-2018-19011 by injecting code into a project file and executing it under the privileges of the application.
5
Where can I find more information about CVE-2018-19011?
You can find more information about CVE-2018-19011 at the following references: http://www.securityfocus.com/bid/106654 and https://ics-cert.us-cert.gov/advisories/ICSA-19-017-01.