PT-2022-1824 · Omron · Cx-Programmer

Michael Heinzl

·

Published

2022-03-04

·

Updated

2022-03-14

·

CVE-2022-25325

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CX-Programmer versions 9.76.1 and earlier
Description The issue is related to a use after free vulnerability, which can be exploited by having a user open a specially crafted CXP file, potentially allowing an attacker to cause information disclosure and/or execute arbitrary code.
Recommendations For CX-Programmer versions 9.76.1 and earlier, consider avoiding the use of specially crafted CXP files until a patch is available. As a temporary workaround, restrict access to files that could potentially exploit this issue to minimize the risk of arbitrary code execution.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01254
CVE-2022-25325

Affected Products

Cx-Programmer