nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-27257 CVE-2020-27257
HIGH
Omron CX-One
Record summary
CVE-2020-27257 has a selected CVSS score of 7.8 (high).
Description
This vulnerability allows local attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can result in a type-confusion condition in the Omron CX-One Version 4.60 and prior devices.
Description source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
CX-OneBrowse Omron / CX-One | CVE List | Through 4.60 | affected |
CX-PositionBrowse Omron / CX-Position | CVE List | Through 2.52 | affected |
CX-ProtocolBrowse Omron / CX-Protocol | CVE List | Through 2.02 | affected |
CX-ServerBrowse Omron / CX-Server | CVE List | Through 5.0.28 | affected |
References
3us-cert.cisa.gov
https://us-cert.cisa.gov/ics/advisories/icsa-21-007-02 zerodayinitiative.com
https://www.zerodayinitiative.com/advisories/ZDI-21-184