CRITICAL
OMRON CX-Programmer Out-of-bounds Write
Published Oct 6, 2022
9.8
CRITICALCVSS 3.1
EPSS 0.71%
Description
OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code.
Affected products
-
Affected
- ≥ unspecified, ≤ 9.78
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Omron | CX-Programmer | unknown | Affected
|
- ≤ 9.78
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Omron has released an update through their Auto Update Service to fix the reported issues. Omron recommends updating to the latest version: Omron CX-Programmer v9.79
For more information, users should see the Omron release note.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42775 Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-277-04 Third Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42775 | Advisory | |
| https://www.cisa.gov/uscert/ics/advisories/icsa-22-277-04 | Third Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Oct 6, 2022
Updated Apr 16, 2025
Reserved Oct 3, 2022
Link CVE-2022-3398
CISA Vulnrichment
Updated Apr 16, 2025
Red Hat
No data
GitHub
No data