PT-2019-9707 · Omron · Cx-Supervisor

Published

2019-01-19

·

Updated

2020-09-18

·

CVE-2018-19015

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OMRON CX-Supervisor versions 3.42 and prior
Description The issue allows an attacker to inject commands and execute code under the privileges of the application through a specially crafted project file. This can be exploited to launch programs, create, write, and read files.
Recommendations For OMRON CX-Supervisor versions 3.42 and prior, consider restricting the use of project files from untrusted sources until a patch is available. As a temporary workaround, consider disabling the GenerateReport API, ViewReport command, WriteMessage function, RunApplication API, MoveFile function, ExecuteJScriptFile command, CopyFile function, EditFile API, and ExecuteVBScriptFile command to minimize the risk of exploitation. Avoid using specially crafted project files in the affected OMRON CX-Supervisor versions until the issue is resolved.

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-19015
ZDI-19-101
ZDI-19-103
ZDI-19-104
ZDI-19-106
ZDI-19-107
ZDI-19-108
ZDI-19-109
ZDI-19-110
ZDI-19-111

Affected Products

Cx-Supervisor