CVE-2023-38748: Use After Free
Published Aug 3, 2023
·Updated
Use after free vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur.
Affected Software
1 affected component
Omron CX-Programmer<=9.80
Event History
Aug 3, 2023
CVE Published
via MITRE·05:09 AM
Data Sourced
via MITRE·05:09 AM
DescriptionWeakness
Data Sourced
06:15 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-38748?
The severity of CVE-2023-38748 is high with a CVSS score of 7.8.
2
Which software is affected by CVE-2023-38748?
The CX-Programmer included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier versions is affected by CVE-2023-38748.
3
What is the impact of CVE-2023-38748?
CVE-2023-38748 can lead to information disclosure and/or arbitrary code execution.
4
How can the vulnerability in CVE-2023-38748 be exploited?
The vulnerability in CVE-2023-38748 can be exploited by having a user open a specially crafted CXP file.
5
How can I fix the vulnerability in CVE-2023-38748?
To fix the vulnerability in CVE-2023-38748, update the CX-One software to version V9.80 or later.