HIGH · 7.8

CVE-2018-7530

Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-Protocol versions 1.992 and prior, CX-Programmer ver...

Vulnerability Description

Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-Protocol versions 1.992 and prior, CX-Programmer versions 9.65 and prior, CX-Server versions 5.0.22 and prior, Network Configurator versions 3.63 and prior, and Switch Box Utility versions 1.68 and prior, may allow the pointer to call an incorrect object resulting in an access of resource using incompatible type condition.

CVSS Score

7.8

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
OmronCx-Flnet<= 1.00
OmronCx-One<= 4.42
OmronCx-Programmer<= 9.65
OmronCx-Protocol<= 1.992
OmronCx-Server<= 5.0.22
OmronNetwork Configurator<= 3.63
OmronSwitch Box Utility<= 1.68

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-7530?

CVE-2018-7530 is a vulnerability with a CVSS score of 7.8 (HIGH). Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-Protocol versions 1.992 and prior, CX-Programmer ver...

How severe is CVE-2018-7530?

CVE-2018-7530 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-7530?

Check the references section above for vendor advisories and patch information. Affected products include: Omron Cx-Flnet, Omron Cx-One, Omron Cx-Programmer, Omron Cx-Protocol, Omron Cx-Server.