ZDI-22-374: Omron CX-One FLN File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Omron CX-One. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of FLN files in the CX-FLnet module. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-22-374?
The severity of ZDI-22-374 is considered high due to its potential for remote code execution.
How do I fix ZDI-22-374?
To fix ZDI-22-374, users should update Omron CX-One to the latest version provided by the vendor.
What type of attack vector is used in ZDI-22-374?
ZDI-22-374 can be exploited through user interaction, requiring the target to visit a malicious page or open a malicious file.
Who is affected by the ZDI-22-374 vulnerability?
The ZDI-22-374 vulnerability affects installations of Omron CX-One software.
What are the potential consequences of ZDI-22-374?
The potential consequences of ZDI-22-374 include arbitrary code execution which could lead to unauthorized access or control over affected systems.