CVE-2020-27259: Omron CX-One NCI File Parsing Untrusted Pointer Dereference Remote Code Execution Vulnerability
The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attacker to remotely execute arbitrary code.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Omron CX-One. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of NCI files by the CX-Position application. The issue results from the lack of proper validation of a user-supplied value prior to dereferencing it as a pointer. An attacker can leverage this vulnerability to execute code in the context of the current process.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-27259?
CVE-2020-27259 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Omron CX-One.
How does CVE-2020-27259 work?
CVE-2020-27259 works by exploiting a flaw in the parsing of NCI files in Omron CX-One, allowing remote attackers to execute arbitrary code.
What is the severity of CVE-2020-27259?
CVE-2020-27259 has a severity rating of 8.8 (high).
Which software products are affected by CVE-2020-27259?
Omron CX-One, Omron CX-Position, Omron Cx-protocol, and Omron Cx-server versions up to inclusive 4.60, 2.52, 2.02, and 5.0.28 respectively are affected by CVE-2020-27259.
How can CVE-2020-27259 be mitigated?
To mitigate CVE-2020-27259, it is recommended to update to the latest version of the affected software and avoid visiting malicious pages or opening malicious files.