CVE Vulnerabilities

CVE-2018-7530

Incorrect Access of Indexable Resource ('Range Error')

Published: Apr 17, 2018 | Modified: Oct 09, 2019
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-Protocol versions 1.992 and prior, CX-Programmer versions 9.65 and prior, CX-Server versions 5.0.22 and prior, Network Configurator versions 3.63 and prior, and Switch Box Utility versions 1.68 and prior, may allow the pointer to call an incorrect object resulting in an access of resource using incompatible type condition.

Weakness

The product does not restrict or incorrectly restricts operations within the boundaries of a resource that is accessed using an index or pointer, such as memory or files.

Affected Software

Name Vendor Start Version End Version
Cx-flnet Omron * 1.00 (including)
Cx-one Omron * 4.42 (including)
Cx-programmer Omron * 9.65 (including)
Cx-protocol Omron * 1.992 (including)
Cx-server Omron * 5.0.22 (including)
Network_configurator Omron * 3.63 (including)
Switch_box_utility Omron * 1.68 (including)

References