First published: Thu Aug 03 2023(Updated: )
Heap-based buffer overflow vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur.
Credit: vultures@jpcert.or.jp vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Omron CX-Programmer | <=9.80 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38747 is a heap-based buffer overflow vulnerability that exists in CX-Programmer included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier.
CVE-2023-38747 has a severity rating of 7.8 (High).
CVE-2023-38747 can be exploited by having a user open a specially crafted CXP file, which may lead to information disclosure and/or arbitrary code execution.
The affected software for CVE-2023-38747 is CX-Programmer included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier versions.
To mitigate CVE-2023-38747, it is recommended to update to a version of CX-One CXONE-AL[][]D-V4 V9.81 or later.