RULE(RULE ID:336695)

Rule General Information
Release Date: 2022-06-28
Rule Name: OMRON CX-One Buffer Error Remote Code Execution Vulnerability (CVE-2022-21137)
Severity:
CVE ID:
Rule Protection Details
Description: Omron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processing specific project files, which may allow an attacker to execute arbitrary code.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Others
Reference: https://www.cisa.gov/uscert/ics/advisories/icsa-22-006-01
ZeroDayInitiative:ZDI-22-373
ZeroDayInitiative:ZDI-22-374
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.omron.com