ZDI-23-224: Omron CX-One CXP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Omron CX-One. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-224?
ZDI-23-224 is assessed as a high severity vulnerability due to its potential for remote code execution.
How do I fix ZDI-23-224?
To fix ZDI-23-224, users should update to the latest version of Omron CX-One that addresses this vulnerability.
What are the potential impacts of ZDI-23-224?
The potential impacts of ZDI-23-224 include unauthorized remote code execution, which could compromise the integrity of the affected system.
Is user interaction required to exploit ZDI-23-224?
Yes, user interaction is required for ZDI-23-224 as the target must visit a malicious page or open a malicious file.
Which software is affected by ZDI-23-224?
ZDI-23-224 affects installations of Omron CX-One, making it vulnerable to exploitation if not properly managed.