#VU17080 Code injection in CX-Supervisor - CVE-2018-19011
Published: January 18, 2019
CX-Supervisor
Omron
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to code injection. A remote unauthenticated attacker can trick the victim into processing a specially crafted processing project files and execute arbitrary code that has been injected into a file under the privileges of the application.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.