CVE-2018-19027: Incorrect Type Cast
Published Jan 30, 2019
·Updated
Three type confusion vulnerabilities exist in CX-One Versions 4.50 and prior and CX-Protocol Versions 2.0 and prior when processing project files. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.
Affected Software
2 affected components
Omron CX-One<=4.50
Omron CX-Protocol<=2.0
Event History
Jan 30, 2019
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of the type confusion vulnerabilities in CX-One and CX-Protocol?
The vulnerability ID is CVE-2018-19027.
2
What are the affected software versions?
The affected software versions are CX-One Versions up to and including 4.50 and CX-Protocol Versions up to and including 2.0.
3
What is the severity rating of CVE-2018-19027?
CVE-2018-19027 has a severity rating of 7.8 (High).
4
How can an attacker exploit the vulnerabilities?
An attacker can exploit the vulnerabilities by using a specially crafted project file.
5
What privileges can an attacker gain when exploiting CVE-2018-19027?
An attacker can execute code under the privileges of the application.