Heap-based buffer overflow vulnerability exists in CX-Drive All models all versions. By having a user open a specially crafted SDD file, arbitrary code may be executed and/or information may be disclosed.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.ia.omron.com/product/vulnerability/OMSR-2023-004_en.pdf | vendor advisory |
https://jvn.jp/en/vu/JVNVU97372625/ | mitigation third party advisory |