CVE-2021-27413: Omron CX-One CX-Position NCI File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
Omron CX-One Versions 4.60 and prior, including CX-Server Versions 5.0.29.0 and prior, are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Omron CX-One. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of NCI files in the CX-Position application. When parsing the BPLCNAME element, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2021-27413.
What is the severity level of CVE-2021-27413?
The severity level of CVE-2021-27413 is high with a score of 7.8.
Which software versions are affected by CVE-2021-27413?
Omron CX-One Versions 4.60 and prior, including CX-Server Versions 5.0.29.0 and prior, are affected by CVE-2021-27413.
What is the impact of CVE-2021-27413?
CVE-2021-27413 allows an attacker to execute arbitrary code due to a stack-based buffer overflow.
Are there any references available for CVE-2021-27413?
Yes, you can find references for CVE-2021-27413 at the following links: 1. [US-CERT Advisory](https://us-cert.cisa.gov/ics/advisories/icsa-21-131-01) 2. [Zero Day Initiative Advisory](https://www.zerodayinitiative.com/advisories/ZDI-21-588/)