PT-2018-2002 · Omron · Omron Cx-One+2

Published

2018-12-04

·

Updated

2020-09-18

·

CVE-2018-18993

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Omron CX-One versions 4.42 and prior Omron CX-Programmer versions 9.66 and prior Omron CX-Server versions 5.0.23 and prior
Description The issue is caused by a stack-based buffer overflow in the Omron CX-Programmer development environment, which is part of the Omron CX-One software suite. This overflow can occur when processing project files, allowing input data to exceed the buffer. An attacker could exploit this by using a specially crafted project file to overflow the buffer and execute arbitrary code under the privileges of the application.
Recommendations For Omron CX-One versions 4.42 and prior, update to a version later than 4.42 to resolve the issue. For Omron CX-Programmer versions 9.66 and prior, update to a version later than 9.66 to resolve the issue. For Omron CX-Server versions 5.0.23 and prior, update to a version later than 5.0.23 to resolve the issue. As a temporary workaround, consider restricting the use of project files from untrusted sources to minimize the risk of exploitation.

Fix

Stack Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-01618
CVE-2018-18993
ZDI-18-1366
ZDI-18-1368

Affected Products

Omron Cx-One
Omron Cx-Programmer
Omron Cx-Server