CVE-2018-8834

Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-Protocol versions 1.992 and prior, CX-Programmer versions 9.65 and prior, CX-Server versions 5.0.22 and prior, Network Configurator versions 3.63 and prior, and Switch Box Utility versions 1.68 and prior, may cause a heap-based buffer overflow.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
icscertCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 30%
VendorProductVersion
omroncx-flnet
𝑥
≤ 1.00
omroncx-one
𝑥
≤ 4.42
omroncx-programmer
𝑥
≤ 9.65
omroncx-protocol
𝑥
≤ 1.992
omroncx-server
𝑥
≤ 5.0.22
omronnetwork_configurator
𝑥
≤ 3.63
omronswitch_box_utility
𝑥
≤ 1.68
𝑥
= Vulnerable software versions