QID 591264

Date Published: 2023-01-12

QID 591264: Omron CX-Programmer Out-of-bounds Write Vulnerability (ICSA-22-356-04)

AFFECTED PRODUCTS
The following Omron product, part of a software automation suite, is affected: Omron CX-Programmer: All versions up to v9.78

QID Detection Logic (Authenticated)
This QID checks for the Vulnerable version using windows registry keys HKLM\SOFTWARE\OMRON\Static Data Provider.

Successful exploitation of this vulnerability could allow arbitrary code execution or loss of sensitive information if a user opens a specially crafted CX-P file.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-22-356-04 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591264

    Software Advisories
    Advisory ID Software Component Link
    ICSA-22-356-04 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-356-04