First published: Tue Feb 12 2019(Updated: )
An access of uninitialized pointer vulnerability in CX-Supervisor (Versions 3.42 and prior) could lead to type confusion when processing project files. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Omron CX-Supervisor | <=3.42 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-19018.
The vulnerability affects CX-Supervisor (Versions 3.42 and prior).
The severity of CVE-2018-19018 is high (7.3).
The CWE ID for this vulnerability is CWE-824.
An attacker can exploit this vulnerability by using a specially crafted project file to execute code under the privileges of the application.