CVE-2022-26419: Omron CX-One CX-Position NCI File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
Omron CX-Position (versions 2.5.3 and prior) is vulnerable to multiple stack-based buffer overflow conditions while parsing a specific project file, which may allow an attacker to locally execute arbitrary code.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Omron CX-One. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of NCI files in the CX-Position module. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-26419?
CVE-2022-26419 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Omron CX-One.
How can this vulnerability be exploited?
To exploit this vulnerability, the target must visit a malicious page or open a malicious file.
Which software installations are affected by CVE-2022-26419?
Omron CX-One installations up to and including version 2.5.3 and Omron CX-Position installations are affected.
What is the severity of CVE-2022-26419?
CVE-2022-26419 has a severity rating of 7.8 (High).
Where can I find more information about CVE-2022-26419?
You can find more information about CVE-2022-26419 at the following references: [1] [2] [3]