ZDI-23-634: Omron CX-One CX-Programmer CXP File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published May 17, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Omron CX-One. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
1 affected component
Omron CX-One
Event History
May 17, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-634?
The severity of ZDI-23-634 is critical due to the potential for remote code execution.
2
How do I fix ZDI-23-634?
To fix ZDI-23-634, users should update to the latest version of Omron CX-One that addresses this vulnerability.
3
Who is affected by ZDI-23-634?
All installations of Omron CX-One are potentially affected by ZDI-23-634.
4
What type of attack does ZDI-23-634 enable?
ZDI-23-634 enables remote attackers to execute arbitrary code on affected systems.
5
Is user interaction required to exploit ZDI-23-634?
Yes, user interaction is required as the target must visit a malicious page or open a malicious file.