CVE-2023-38746: High severity omron cx-programmer vulnerability
Published Aug 3, 2023
·Updated
Out-of-bounds read vulnerability/issue exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur.
Affected Software
1 affected component
Omron CX-Programmer<=9.80
Event History
Aug 3, 2023
CVE Published
via MITRE·04:58 AM
Data Sourced
via MITRE·04:58 AM
DescriptionWeakness
Data Sourced
05:15 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-38746.
2
What is the severity of CVE-2023-38746?
The severity of CVE-2023-38746 is high with a CVSS score of 7.8.
3
What is the affected software by CVE-2023-38746?
The affected software by CVE-2023-38746 is CX-Programmer included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by having a user open a specially crafted CXP file, which may lead to information disclosure and/or arbitrary code execution.
5
Is there a fix for CVE-2023-38746?
Yes, the vendor has provided a fix for CVE-2023-38746. Please refer to the vendor's advisory for more information.