ZDI-23-223: Omron CX-One CXP File Parsing Memory Corruption Remote Code Execution Vulnerability
Published Mar 7, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Omron CX-One. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
1 affected component
Omron CX-One
Event History
Mar 7, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-223?
The severity of ZDI-23-223 is critical due to its potential to allow remote code execution.
2
How do I fix ZDI-23-223?
To fix ZDI-23-223, update Omron CX-One to the latest version that addresses this vulnerability.
3
What types of attacks can be executed using ZDI-23-223?
ZDI-23-223 allows remote attackers to execute arbitrary code, leading to potential data loss or system compromise.
4
Is user interaction required to exploit ZDI-23-223?
Yes, user interaction is required as the target must visit a malicious page or open a malicious file to exploit ZDI-23-223.
5
Which software is affected by ZDI-23-223?
ZDI-23-223 affects installations of Omron CX-One.