CVE-2020-27261: Omron CX-One NCI File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
The Omron CX-One Version 4.60 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Omron CX-One. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of NCI files by the CX-Position application. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-27261?
CVE-2020-27261 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Omron CX-One.
How can the CVE-2020-27261 vulnerability be exploited?
The CVE-2020-27261 vulnerability requires user interaction, such as visiting a malicious page or opening a malicious file, to be exploited.
Which software installations are affected by CVE-2020-27261?
The CVE-2020-27261 vulnerability affects installations of Omron CX-One, Omron CX-Position, Omron Cx-protocol, and Omron Cx-server.
What is the severity of CVE-2020-27261?
CVE-2020-27261 has a severity rating of 8.8 (High).
Are there any recommended mitigations or fixes for CVE-2020-27261?
It is recommended to apply the necessary updates and security patches provided by Omron to mitigate the vulnerability.