HTTP: OMRON CX-One CX-Programmer Program Use After Free
This signature detects attempts to exploit a known vulnerability against OMRON CX-One CX-Programmer module. The vulnerability is due to input validation error when processing Program parameter of the CX-Programmer project files. A remote attacker could exploit this vulnerability by enticing a target user into opening a maliciously crafted project file. Successful exploitation could result in arbitrary code execution in the context of the target user.
Extended Description
When processing project files, the application (Omron CX-Programmer v9.70 and prior and Common Components January 2019 and prior) fails to check if it is referencing freed memory. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.
Affected Products
Omron common_components
References
CVE: CVE-2019-6556
mx-19.3
vmx-19.3
vsrx-19.2
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-19.4
vsrx3bsd-19.4
srx-branch-19.4
vsrx-19.4
vmx-19.4
mx-19.4
srxevo-25.4
vsrx-26.2
srx-26.2
srx-branch-26.2
vsrx3bsd-26.2
mx-12.3
srx-12.3
srx-branch-12.3
vsrx-12.3
Omron
6.8