In Omron CX-Supervisor Versions 3.30 and prior, access of uninitialized pointer vulnerabilities can be exploited when CX Supervisor indirectly calls an initialized pointer when parsing malformed packets.
Storing a password in plaintext may result in a system compromise.
The product accesses or uses a pointer that has not been initialized.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/103394 | vdb entry third party advisory |
https://ics-cert.us-cert.gov/advisories/ICSA-18-072-01 | us government resource third party advisory mitigation |