ZDI-21-182: Omron CX-One NCI File Parsing Untrusted Pointer Dereference Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Omron CX-One. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of NCI files by the CX-Position application. The issue results from the lack of proper validation of a user-supplied value prior to dereferencing it as a pointer. An attacker can leverage this vulnerability to execute code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-21-182?
The severity of ZDI-21-182 is significant due to the potential for remote code execution.
How do I fix ZDI-21-182?
To fix ZDI-21-182, ensure that you update Omron CX-One to the latest version provided by the vendor.
What are the potential impacts of ZDI-21-182?
The potential impacts of ZDI-21-182 include unauthorized remote code execution on affected systems.
Is user interaction required for ZDI-21-182 exploitation?
Yes, user interaction is required for ZDI-21-182 exploitation as the target must visit a malicious page or open a malicious file.
Which product is affected by ZDI-21-182?
The product affected by ZDI-21-182 is Omron CX-One.