HIGH
Omron CX-One
Published Jan 14, 2022
7.8
HIGHCVSS 3.1
EPSS 9.27%
Description
Omron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processing specific project files, which may allow an attacker to execute arbitrary code.
Affected products
-
- Version AllStatusaffectedConstraints<=4.60
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Omron has released an updated version of CX-One to address the reported vulnerability. The following release is available through the CX-One auto-update service: CX-Server: Version 5.0.29.2
Weaknesses (2)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-26384 Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-006-01 x_refsource_MISCThird Party AdvisoryUS Government Resource
- https://www.zerodayinitiative.com/advisories/ZDI-22-373/ x_refsource_MISCThird Party AdvisoryVDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-22-374/ x_refsource_MISCThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-26384 | Advisory | |
| https://www.cisa.gov/uscert/ics/advisories/icsa-22-006-01 | x_refsource_MISCThird Party AdvisoryUS Government Resource | |
| https://www.zerodayinitiative.com/advisories/ZDI-22-373/ | x_refsource_MISCThird Party AdvisoryVDB Entry | |
| https://www.zerodayinitiative.com/advisories/ZDI-22-374/ | x_refsource_MISCThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Jan 14, 2022
Updated Apr 16, 2025
Reserved Dec 21, 2021
Link CVE-2022-21137
CISA Vulnrichment
Updated Apr 16, 2025
ENISA EUVD
EUVD-2022-26384 Assigner icscert
Published Jan 14, 2022
Updated Apr 16, 2025
Exploited since n/a
Link EUVD-2022-26384