ZDI-CAN-15484: ZDI-23-634: Omron CX-One CX-Programmer CXP File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published May 17, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Omron CX-One. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
1 affected component
Omron CX-One
Event History
May 17, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-15484?
The severity of ZDI-CAN-15484 is critical due to its ability to allow remote code execution.
2
How do I fix ZDI-CAN-15484?
To fix ZDI-CAN-15484, users should update Omron CX-One to the latest version provided by the vendor.
3
What type of attacks does ZDI-CAN-15484 enable?
ZDI-CAN-15484 enables remote code execution attacks requiring user interaction.
4
What versions of Omron CX-One are affected by ZDI-CAN-15484?
All installations of Omron CX-One are affected by ZDI-CAN-15484.
5
Is user interaction required to exploit ZDI-CAN-15484?
Yes, user interaction is required as the target must visit a malicious page or open a malicious file.