First published: Thu Aug 03 2023(Updated: )
Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22277 and CVE-2023-22314.
Credit: vultures@jpcert.or.jp vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Omron CX-Programmer | <=9.79 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-22317.
The severity of CVE-2023-22317 is high, with a CVSS score of 7.8.
CX-Programmer Ver.9.79 and earlier versions are affected by CVE-2023-22317.
An attacker can exploit CVE-2023-22317 by having a user open a specially crafted CXP file, which may lead to information disclosure and/or arbitrary code execution.
CVE-2023-22317 is different from CVE-2023-22277 and CVE-2023-22314.