PT-2019-18164 · Omron · Omron Cx-Programmer+1
Esteban Ruiz
+1
·
Published
2019-04-10
·
Updated
2019-04-15
·
CVE-2019-6556
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Omron CX-Programmer versions 9.70 and prior
Common Components versions January 2019 and prior
Description
The issue arises when the application processes project files, specifically due to a failure in checking references to freed memory. This can be exploited by an attacker using a specially crafted project file, potentially leading to the execution of code under the application's privileges.
Recommendations
For Omron CX-Programmer versions 9.70 and prior, consider disabling the project file processing feature until a patch is available.
For Common Components versions January 2019 and prior, restrict access to project file parsing functionality to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Common Components
Omron Cx-Programmer