First published: Fri Apr 01 2022(Updated: )
Omron CX-Position (versions 2.5.3 and prior) is vulnerable to a use after free memory condition while processing a specific project file, which may allow an attacker to execute arbitrary code.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Omron CX-Position | <=2.5.3 | |
Omron CX-Position Versions 2.5.3 and prior | ||
Omron has provided Version 2.5.4, which is only available to paying users who use the “Auto Update” function. Please contact Omron technical Support or an Omron representative for specific update information.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-26417 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Omron CX-One.
This vulnerability can be exploited by remote attackers through user interaction, such as visiting a malicious page or opening a malicious file.
The affected software is Omron CX-One with a version up to and including 2.5.3.
The severity of CVE-2022-26417 is high, with a CVSS score of 7.8.
To fix CVE-2022-26417, it is recommended to update the affected software to a version that includes a patch or mitigation provided by the vendor.