CVE-2020-27257: Omron CX-One PSW File Parsing Type Confusion Remote Code Execution Vulnerability
This vulnerability allows local attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can result in a type-confusion condition in the Omron CX-One Version 4.60 and prior devices.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Omron CX-One. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PSW files by the CX-Protocol application. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2020-27257.
What is the severity of CVE-2020-27257?
The severity of CVE-2020-27257 is high with a CVSS score of 7.8.
Which software products are affected by CVE-2020-27257?
Omron CX-One, Omron CX-Position, Omron CX-Protocol, and Omron CX-Server are affected by CVE-2020-27257.
How does the vulnerability CVE-2020-27257 work?
CVE-2020-27257 is a type confusion vulnerability that allows remote attackers to execute arbitrary code on affected installations of Omron CX-One by exploiting a flaw in the parsing of PSW files.
How can CVE-2020-27257 be exploited?
To exploit CVE-2020-27257, the attacker requires the target to visit a malicious page or open a malicious PSW file.