Back to Database
Status published
Low
CVE-2018-17907
When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and...
Vulnerability Description
When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with the value of an offset, an attacker can force the application to read a value outside of an array.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-17907
Credits & Attribution
No credits recorded in the NVD database.
References
More from Omron
View All →CVE-2022-45794
Omron CJ-series and CS-series unauthenticated filesystem access.
High
8.6
CVE-2022-45793
Executable files writable by low-privileged users in Omron Sysmac Studio
Medium
5.5
CVE-2022-45792
Directory Traversal in Project File Format allows overwrite (Zip Slip)
High
7.8
CVE-2022-45790
Omron FINS memory protection susceptible to bruteforce
High
8.6
CVE-2022-2979
Omron CX-Programmer
High
7.8
Affected Vendor
Omron
View all reports →Affected Software
CX-Supervisor
Vulnerable Versions:
Versions 3.4.1.0 and prior.
Timeline
Official Publish:
November 5th, 2018
Last Modified:
September 17th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N