HTTP: OMRON CX-One CX-Programmer Program Use After Free
This signature detects attempts to exploit a known vulnerability against OMRON CX-One CX-Programmer module. The vulnerability is due to input validation error when processing Program parameter of the CX-Programmer project files. A remote attacker could exploit this vulnerability by enticing a target user into opening a maliciously crafted project file. Successful exploitation could result in arbitrary code execution in the context of the target user.
Extended Description
When processing project files, the application (Omron CX-Programmer v9.70 and prior and Common Components January 2019 and prior) fails to check if it is referencing freed memory. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.
Affected Products
Omron common_components
References
CVE: CVE-2019-6556
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Omron
6.8