« Volver al listado

CVE-2024-31413

Estado: AplazadaMedia (5.9)—

Free of pointer not at start of buffer vulnerability exists in CX-One CX-One CXONE-AL[][]D-V4 (The version which was installed with a DVD ver. 4.61.1 or lower, and was updated through CX-One V4 auto update in January 2024 or prior) and Sysmac Studio SYSMAC-SE2[][][] (The version which was installed with a DVD ver. 1.56 or lower, and was updated through Sysmac Studio V1 auto update in January 2024 or prior). Opening a specially crafted project file may lead to arbitrary code execution.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-31413",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-31413",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-05-01T14:49:56.532150Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.9,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 2.5
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "OMRON Corporation",
          "product": "CX-One CX-One CXONE-AL[][]D-V4 ",
          "versions": [
            {
              "status": "affected",
              "version": "The version which was installed with a DVD ver. 4.61.1 or lower"
            },
            {
              "status": "affected",
              "version": " and was updated through CX-One V4 auto update in January 2024 or prior"
            }
          ]
        },
        {
          "vendor": "OMRON Corporation",
          "product": "Sysmac Studio SYSMAC-SE2[][][] ",
          "versions": [
            {
              "status": "affected",
              "version": "The version which was installed with a DVD ver. 1.56 or lower"
            },
            {
              "status": "affected",
              "version": " and was updated through Sysmac Studio V1 auto update in January 2024 or prior"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:omrom:cx-designer:*:*:*:*:*:*:*:*"
          ],
          "vendor": "omrom",
          "product": "cx-designer",
          "versions": [
            {
              "status": "affected",
              "version": "*"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-05-01T13:15:52.080",
  "references": [
    {
      "url": "https://jvn.jp/en/vu/JVNVU98274902/",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2024-002_en.pdf",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/vu/JVNVU98274902/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2024-002_en.pdf",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-761"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Free of pointer not at start of buffer vulnerability exists in CX-One CX-One CXONE-AL[][]D-V4 (The version which was installed with a DVD ver. 4.61.1 or lower, and was updated through CX-One V4 auto update in January 2024 or prior) and Sysmac Studio SYSMAC-SE2[][][] (The version which was installed with a DVD ver. 1.56 or lower, and was updated through Sysmac Studio V1 auto update in January 2024 or prior). Opening a specially crafted project file may lead to arbitrary code execution."
    },
    {
      "lang": "es",
      "value": "Existe una vulnerabilidad libre de puntero que no está al inicio del búfer en CX-One CX-One CXONE-AL[][]D-V4 (la versión que se instaló con un DVD versión 4.61.1 o inferior y se actualizó a través de CX- Una actualización automática de V4 en enero de 2024 o antes) y Sysmac Studio SYSMAC-SE2[][][] (la versión que se instaló con un DVD versión 1.56 o anterior y se actualizó mediante la actualización automática de Sysmac Studio V1 en enero de 2024 o antes). previo). Abrir un archivo de proyecto especialmente manipulado puede provocar la ejecución de código arbitrario."
    }
  ],
  "lastModified": "2026-06-17T07:28:23.680",
  "sourceIdentifier": "vultures@jpcert.or.jp"
}