First published: Tue Apr 17 2018(Updated: )
Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-Protocol versions 1.992 and prior, CX-Programmer versions 9.65 and prior, CX-Server versions 5.0.22 and prior, Network Configurator versions 3.63 and prior, and Switch Box Utility versions 1.68 and prior, may cause a stack-based buffer overflow.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Omron Cx-flnet | <=1.00 | |
Omron CX-One | <=4.42 | |
Omron CX-Programmer | <=9.65 | |
Omron Cx-protocol | <=1.992 | |
Omron Cx-server | <=5.0.22 | |
Omron Network Configurator | <=3.63 | |
Omron Switch Box Utility | <=1.68 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security issue is CVE-2018-7514.
The severity of CVE-2018-7514 is high with a score of 7.8.
Omron CX-One versions 4.42 and prior are affected by CVE-2018-7514.
The following applications within Omron CX-One are affected by CVE-2018-7514: CX-FLnet versions 1.00 and prior, CX-Protocol versions 1.992 and prior, CX-Programmer versions 9.65 and prior, CX-Server versions 5.0.22 and prior, Network Configurator versions 3.63 and prior.
You can find more information about CVE-2018-7514 at the following reference: [https://ics-cert.us-cert.gov/advisories/ICSA-18-100-02](https://ics-cert.us-cert.gov/advisories/ICSA-18-100-02)