PT-2018-18119 · Omron · Switch Box Utility+6
Rgod
·
Publicado
2018-04-11
·
Atualizado
2020-10-02
·
CVE-2018-7514
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Omron CX-One versions 4.42 and prior
CX-FLnet versions 1.00 and prior
CX-Protocol versions 1.992 and prior
CX-Programmer versions 9.65 and prior
CX-Server versions 5.0.22 and prior
Network Configurator versions 3.63 and prior
Switch Box Utility versions 1.68 and prior
Description
The issue is related to parsing malformed project files, which may cause a stack-based buffer overflow. This can potentially lead to remote code execution. The vulnerability is identified in various applications within the Omron CX-One suite.
Recommendations
For Omron CX-One versions 4.42 and prior, update to a version later than 4.42 to resolve the issue.
For CX-FLnet versions 1.00 and prior, update to a version later than 1.00 to resolve the issue.
For CX-Protocol versions 1.992 and prior, update to a version later than 1.992 to resolve the issue.
For CX-Programmer versions 9.65 and prior, update to a version later than 9.65 to resolve the issue.
For CX-Server versions 5.0.22 and prior, update to a version later than 5.0.22 to resolve the issue.
For Network Configurator versions 3.63 and prior, update to a version later than 3.63 to resolve the issue.
For Switch Box Utility versions 1.68 and prior, update to a version later than 1.68 to resolve the issue.
Correção
Stack Overflow
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cx-Flnet
Cx-One
Cx-Programmer
Cx-Protocol
Cx-Server
Network Configurator
Switch Box Utility