Omron Cx-One vulnerabilities
11 known vulnerabilities affecting omron/cx-one.
Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH11
Vulnerabilities
Page 1 of 1
CVE-2020-27261P3HIGHCVSS 8.8≤ 4.60≥ unspecified, ≤ 4.602021-02-09
CVE-2020-27261 [HIGH] CWE-121 CVE-2020-27261: The Omron CX-One Version 4.60 and prior is vulnerable to a stack-based buffer overflow, which may al
The Omron CX-One Version 4.60 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.
nvd
CVE-2020-27259P3HIGHCVSS 8.8≤ 4.60≥ unspecified, ≤ 4.602021-02-09
CVE-2020-27259 [HIGH] CWE-822 CVE-2020-27259: The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memor
The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attacker to remotely execute arbitrary code.
nvd
CVE-2021-27413P3HIGHCVSS 7.8≤ 4.602021-05-13
CVE-2021-27413 [HIGH] CWE-121 CVE-2021-27413: Omron CX-One Versions 4.60 and prior, including CX-Server Versions 5.0.29.0 and prior, are vulnerabl
Omron CX-One Versions 4.60 and prior, including CX-Server Versions 5.0.29.0 and prior, are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.
nvd
CVE-2022-21137P3HIGHCVSS 7.8≤ 4.60≥ All, ≤ 4.602022-01-14
CVE-2022-21137 [HIGH] CWE-121 CVE-2022-21137: Omron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processin
Omron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processing specific project files, which may allow an attacker to execute arbitrary code.
nvd
CVE-2020-27257P3HIGHCVSS 7.8≤ 4.60≥ unspecified, ≤ 4.602021-02-09
CVE-2020-27257 [HIGH] CWE-843 CVE-2020-27257: This vulnerability allows local attackers to execute arbitrary code due to the lack of proper valida
This vulnerability allows local attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can result in a type-confusion condition in the Omron CX-One Version 4.60 and prior devices.
nvd
CVE-2018-18993P3HIGHCVSS 7.8≤ 4.422018-12-04
CVE-2018-18993 [HIGH] CWE-121 CVE-2018-18993: Two stack-based buffer overflow vulnerabilities have been discovered in CX-One Versions 4.42 and pri
Two stack-based buffer overflow vulnerabilities have been discovered in CX-One Versions 4.42 and prior (CX-Programmer Versions 9.66 and prior and CX-Server Versions 5.0.23 and prior). When processing project files, the application allows input data to exceed the buffer. An attacker could use a specially crafted project file to overflow the buffer and
nvd
CVE-2018-19027P3HIGHCVSS 7.8≤ 4.502019-01-30
CVE-2018-19027 [HIGH] CWE-843 CVE-2018-19027: Three type confusion vulnerabilities exist in CX-One Versions 4.50 and prior and CX-Protocol Version
Three type confusion vulnerabilities exist in CX-One Versions 4.50 and prior and CX-Protocol Versions 2.0 and prior when processing project files. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.
nvd
CVE-2018-18989P3HIGHCVSS 7.8≤ 4.422018-12-04
CVE-2018-18989 [HIGH] CWE-416 CVE-2018-18989: In CX-One Versions 4.42 and prior (CX-Programmer Versions 9.66 and prior and CX-Server Versions 5.0.
In CX-One Versions 4.42 and prior (CX-Programmer Versions 9.66 and prior and CX-Server Versions 5.0.23 and prior), when processing project files, the application fails to check if it is referencing freed memory. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.
nvd
CVE-2018-7530P3HIGHCVSS 7.8≤ 4.422018-04-17
CVE-2018-7530 [HIGH] CWE-843 CVE-2018-7530: Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following app
Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-Protocol versions 1.992 and prior, CX-Programmer versions 9.65 and prior, CX-Server versions 5.0.22 and prior, Network Configurator versions 3.63 and prior, and Switch Box Utility versions 1.68 and prior, ma
nvd
CVE-2018-8834P3HIGHCVSS 7.8≤ 4.422018-04-17
CVE-2018-8834 [HIGH] CWE-122 CVE-2018-8834: Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following app
Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-Protocol versions 1.992 and prior, CX-Programmer versions 9.65 and prior, CX-Server versions 5.0.22 and prior, Network Configurator versions 3.63 and prior, and Switch Box Utility versions 1.68 and prior, ma
nvd
CVE-2018-7514P3HIGHCVSS 7.8≤ 4.422018-04-17
CVE-2018-7514 [HIGH] CWE-121 CVE-2018-7514: Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following app
Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-Protocol versions 1.992 and prior, CX-Programmer versions 9.65 and prior, CX-Server versions 5.0.22 and prior, Network Configurator versions 3.63 and prior, and Switch Box Utility versions 1.68 and prior, ma
nvd