CVE-2018-7514
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
17/04/2018
Last modified:
02/10/2020
Description
Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-Protocol versions 1.992 and prior, CX-Programmer versions 9.65 and prior, CX-Server versions 5.0.22 and prior, Network Configurator versions 3.63 and prior, and Switch Box Utility versions 1.68 and prior, may cause a stack-based buffer overflow.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:omron:cx-flnet:*:*:*:*:*:*:*:* | 1.00 (including) | |
cpe:2.3:a:omron:cx-one:*:*:*:*:*:*:*:* | 4.42 (including) | |
cpe:2.3:a:omron:cx-programmer:*:*:*:*:*:*:*:* | 9.65 (including) | |
cpe:2.3:a:omron:cx-protocol:*:*:*:*:*:*:*:* | 1.992 (including) | |
cpe:2.3:a:omron:cx-server:*:*:*:*:*:*:*:* | 5.0.22 (including) | |
cpe:2.3:a:omron:network_configurator:*:*:*:*:*:*:*:* | 3.63 (including) | |
cpe:2.3:a:omron:switch_box_utility:*:*:*:*:*:*:*:* | 1.68 (including) |
To consult the complete list of CPE names with products and versions, see this page