First published: Thu Aug 03 2023(Updated: )
Use after free vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur.
Credit: vultures@jpcert.or.jp vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Omron CX-Programmer | <=9.80 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-38748 is high with a CVSS score of 7.8.
The CX-Programmer included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier versions is affected by CVE-2023-38748.
CVE-2023-38748 can lead to information disclosure and/or arbitrary code execution.
The vulnerability in CVE-2023-38748 can be exploited by having a user open a specially crafted CXP file.
To fix the vulnerability in CVE-2023-38748, update the CX-One software to version V9.80 or later.