First published: Tue Mar 29 2022(Updated: )
Omron CX-Position (versions 2.5.3 and prior) is vulnerable to memory corruption while processing a specific project file, which may allow an attacker to execute arbitrary code.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Omron CX-Position | <=2.5.3 | |
Omron CX-One | ||
Omron CX-Position Versions 2.5.3 and prior |
Omron has provided Version 2.5.4, which is only available to paying users who use the “Auto Update” function. Please contact Omron technical Support or an Omron representative for specific update information.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID of this vulnerability is CVE-2022-25959.
The title of this vulnerability is 'Omron CX-One CX-Position NCI File Parsing Memory Corruption Remote Code Execution Vulnerability'.
The affected software is Omron CX-One (up to version 2.5.3) and Omron CX-Position.
This vulnerability has a severity score of 7.8 (high).
To exploit this vulnerability, user interaction is required. The target must visit a malicious page or open a malicious file.