PT-2019-18164 · Omron · Omron Cx-Programmer+1

Esteban Ruiz

+1

·

Publicado

2019-04-10

·

Atualizado

2019-04-15

·

CVE-2019-6556

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Omron CX-Programmer versions 9.70 and prior Common Components versions January 2019 and prior
Description The issue arises when the application processes project files, specifically due to a failure in checking references to freed memory. This can be exploited by an attacker using a specially crafted project file, potentially leading to the execution of code under the application's privileges.
Recommendations For Omron CX-Programmer versions 9.70 and prior, consider disabling the project file processing feature until a patch is available. For Common Components versions January 2019 and prior, restrict access to project file parsing functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-6556
ZDI-19-344

Produtos afetados

Common Components
Omron Cx-Programmer