CVE-2021-20836: Medium severity omron cx-supervisor vulnerability
Published Oct 19, 2021
·Updated
Out-of-bounds read vulnerability in CX-Supervisor v4.0.0.13 and v4.0.0.16 allows an attacker with administrative privileges to cause information disclosure and/or arbitrary code execution by opening a specially crafted SCS project files.
Affected Software
2 affected components
Omron CX-Supervisor=4.0.0.13
Omron CX-Supervisor=4.0.0.16
Remediation
Patch Available
Event History
Oct 19, 2021
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this out-of-bounds read vulnerability?
The vulnerability ID is CVE-2021-20836.
2
Which software versions are affected by this vulnerability?
CX-Supervisor v4.0.0.13 and v4.0.0.16 are affected by this vulnerability.
3
What can an attacker with administrative privileges do with this vulnerability?
An attacker with administrative privileges can cause information disclosure and/or arbitrary code execution.
4
How can I fix this vulnerability?
Upgrade CX-Supervisor to a version that is not affected by this vulnerability.
5
What is the severity of CVE-2021-20836?
The severity of CVE-2021-20836 is medium with a CVSS score of 6.5.