Omron.CX-One.CX-Protocol.CSCU.Type.Confusion

description-logoDescription

This indicates an attack attempt to exploit a Type Confusion Vulnerability in OMRON CX-One CX-Protocol.
A remote attacker may exploit this vulnerability by enticing the victim to open a CX-Protocol application with a crafted project file using the vulnerable version of the software. Successful exploitation could lead to code execution under the security context of the user. Unsuccessful exploitation would lead to a hang or termination of the application.

affected-products-logoAffected Products

OMRON CX-One CX-Protocol Versions 2.0 and prior

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Refer to the ICS-CERT advisory for updates.
https://ics-cert.us-cert.gov/advisories/ICSA-19-010-02

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2019-10-24 14.710 Default_action:pass:drop
2019-06-25 14.638

References

ICSA-19-010-02