Omron
Omron Cx-programmer: vulnerabilidades y CVE
Omron Cx-programmer tiene 30 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE30
Últimos 12 meses0
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-0591 | Alta (7.8) | 0.18% | — | 17 feb 2025 | Out-of-bounds Read vulnerability (CWE-125) was found in CX-Programmer. Attackers may be able to read sensitive information or cause an application crash by abusing this vulnerability. |
| CVE-2024-31412 | Alta (7.8) | 0.24% | — | 1 may 2024 | Out-of-bounds read vulnerability exists in CX-Programmer included in CX-One CXONE-AL[][]D-V4 Ver. 9.81 or lower. Opening a specially crafted project file may lead to information disclosure and/or the product being… |
| CVE-2023-22277 | Alta (7.8) | 0.24% | — | 3 ago 2023 | Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is… |
| CVE-2023-22317 | Alta (7.8) | 0.24% | — | 3 ago 2023 | Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is… |
| CVE-2023-22314 | Alta (7.8) | 0.24% | — | 3 ago 2023 | Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is… |
| CVE-2023-38748 | Alta (7.8) | 0.22% | — | 3 ago 2023 | Use after free vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may… |
| CVE-2023-38747 | Alta (7.8) | 0.24% | — | 3 ago 2023 | Heap-based buffer overflow vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code… |
| CVE-2023-38746 | Alta (7.8) | 0.22% | — | 3 ago 2023 | Out-of-bounds read vulnerability/issue exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code… |
| CVE-2022-43667 | Alta (7.8) | 0.28% | — | 7 dic 2022 | Stack-based buffer overflow vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. |
| CVE-2022-43509 | Alta (7.8) | 0.25% | — | 7 dic 2022 | Out-of-bounds write vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. |
| CVE-2022-43508 | Alta (7.8) | 0.26% | — | 7 dic 2022 | Use-after free vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. |
| CVE-2022-3398 | Crítica (9.8) | 0.61% | — | 6 oct 2022 | OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code. |
| CVE-2022-3397 | Crítica (9.8) | 0.61% | — | 6 oct 2022 | OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code. |
| CVE-2022-3396 | Crítica (9.8) | 0.61% | — | 6 oct 2022 | OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code. |
| CVE-2022-2979 | Alta (7.8) | 0.25% | — | 12 sept 2022 | Opening a specially crafted file could cause the affected product to fail to release its memory reference potentially resulting in arbitrary code execution. |
| CVE-2022-31204 | Alta (7.5) | 0.65% | — | 26 jul 2022 | Omron CS series, CJ series, and CP series PLCs through 2022-05-18 use cleartext passwords. They feature a UM Protection setting that allows users or system integrators to configure a password in order to restrict… |
| CVE-2022-25325 | Alta (7.8) | 1.1% | — | 10 mar 2022 | Use after free vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a… |
| CVE-2022-25234 | Alta (7.8) | 1.0% | — | 10 mar 2022 | Out-of-bounds write vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open… |
| CVE-2022-25230 | Alta (7.8) | 1.1% | — | 10 mar 2022 | Use after free vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a… |
| CVE-2022-21219 | Alta (7.8) | 1.0% | — | 10 mar 2022 | Out-of-bounds read vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a… |
| CVE-2022-21124 | Alta (7.8) | 1.5% | — | 10 mar 2022 | Out-of-bounds write vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open… |
| CVE-2019-6556 | Media (6.6) | 1.2% | — | 10 abr 2019 | When processing project files, the application (Omron CX-Programmer v9.70 and prior and Common Components January 2019 and prior) fails to check if it is referencing freed memory. An attacker could use a specially… |
| CVE-2018-18993 | Alta (7.8) | 1.8% | — | 4 dic 2018 | Two stack-based buffer overflow vulnerabilities have been discovered in CX-One Versions 4.42 and prior (CX-Programmer Versions 9.66 and prior and CX-Server Versions 5.0.23 and prior). When processing project files, the… |
| CVE-2018-18989 | Alta (7.8) | 1.6% | — | 4 dic 2018 | In CX-One Versions 4.42 and prior (CX-Programmer Versions 9.66 and prior and CX-Server Versions 5.0.23 and prior), when processing project files, the application fails to check if it is referencing freed memory. An… |
| CVE-2018-8834 | Alta (7.8) | 0.32% | — | 17 abr 2018 | Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-Protocol versions 1.992 and prior, CX-Programmer versions 9.65 and… |
| CVE-2018-7530 | Alta (7.8) | 0.33% | — | 17 abr 2018 | Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-Protocol versions 1.992 and prior, CX-Programmer versions 9.65 and… |
| CVE-2018-7514 | Alta (7.8) | 0.32% | — | 17 abr 2018 | Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-Protocol versions 1.992 and prior, CX-Programmer versions 9.65 and… |
| CVE-2015-1015 | Baja (2.1) | 0.40% | — | 6 oct 2015 | Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 use a reversible format for password storage in object files on Compact Flash cards, which makes it easier for local… |
| CVE-2015-0988 | Baja (2.1) | 0.33% | — | 6 oct 2015 | Omron CX-One CX-Programmer before 9.6 uses a reversible format for password storage in project source-code files, which makes it easier for local users to obtain sensitive information by reading a file. |
| CVE-2015-0987 | Crítica (10) | 1.2% | — | 6 oct 2015 | Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission, which allows remote attackers to obtain sensitive information by sniffing the… |