#VU49341 Untrusted Pointer Dereference in CX-One - CVE-2020-27259
Published: January 8, 2021
CX-One
Omron
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to untrusted pointer dereference when processing certain files. A remote attacker can trick the victim to open a specially crafted file, trigger the untrusted Pointer dereference error and execute arbitrary code on the system.
Remediation
Omron has released an updated version of CX-One to address the reported vulnerabilities. These releases are available through the CX-One auto-update service and are as follows:
- CX-Protocol Version 2.03
- CX-Server Version 5.0.29
- CX-Position Version 2.53