First published: Thu Aug 03 2023(Updated: )
Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22277 and CVE-2023-22317.
Credit: vultures@jpcert.or.jp vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Omron CX-Programmer | <=9.79 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-22314 is high with a CVSS score of 7.8.
The use after free vulnerability in CX-Programmer Ver.9.79 and earlier occurs when a user opens a specially crafted CXP file.
The potential consequences of CVE-2023-22314 include information disclosure and/or arbitrary code execution.
Yes, CVE-2023-22314 is different from CVE-2023-22277 and CVE-2023-22317.
To fix the use after free vulnerability in CX-Programmer Ver.9.79 and earlier, users should update to a version newer than 9.79.