ZDI-23-222: Omron CX-One CXP File Parsing Memory Corruption Remote Code Execution Vulnerability
Published Mar 7, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Omron CX-One. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
1 affected component
Omron CX-One
Event History
Mar 7, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-222?
The severity of ZDI-23-222 is considered critical due to the potential for remote code execution.
2
How do I fix ZDI-23-222?
To fix ZDI-23-222, update your Omron CX-One software to the latest version provided by the vendor.
3
Who is affected by ZDI-23-222?
Users of Omron CX-One installations are affected by ZDI-23-222.
4
What exploitation methods are used in ZDI-23-222?
ZDI-23-222 can be exploited through user interaction via a malicious webpage or a malicious file.
5
What can happen if ZDI-23-222 is exploited?
If ZDI-23-222 is exploited, attackers can execute arbitrary code on the affected system.