VYPR

CX-Position

by Omron

CVEs (7)

  • CVE-2020-27261HigFeb 9, 2021
    risk 0.58cvss 8.8epss 0.08

    The Omron CX-One Version 4.60 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2020-27259HigFeb 9, 2021
    risk 0.57cvss 8.8epss 0.03

    The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2022-26419HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.02

    Omron CX-Position (versions 2.5.3 and prior) is vulnerable to multiple stack-based buffer overflow conditions while parsing a specific project file, which may allow an attacker to locally execute arbitrary code.

  • CVE-2022-26417HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.01

    Omron CX-Position (versions 2.5.3 and prior) is vulnerable to a use after free memory condition while processing a specific project file, which may allow an attacker to execute arbitrary code.

  • CVE-2022-26022HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.01

    Omron CX-Position (versions 2.5.3 and prior) is vulnerable to an out-of-bounds write while processing a specific project file, which may allow an attacker to execute arbitrary code.

  • CVE-2022-25959HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.01

    Omron CX-Position (versions 2.5.3 and prior) is vulnerable to memory corruption while processing a specific project file, which may allow an attacker to execute arbitrary code.

  • CVE-2020-27257HigFeb 9, 2021
    risk 0.51cvss 7.8epss 0.02

    This vulnerability allows local attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can result in a type-confusion condition in the Omron CX-One Version 4.60 and prior devices.