5.3

CVE-2018-7515

In Omron CX-Supervisor Versions 3.30 and prior, access of uninitialized pointer vulnerabilities can be exploited when CX Supervisor indirectly calls an initialized pointer when parsing malformed packets.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OmronCx-supervisor Version <= 3.30
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.215
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 1.8 3.4
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-256 Plaintext Storage of a Password

Storing a password in plaintext may result in a system compromise.

CWE-824 Access of Uninitialized Pointer

The product accesses or uses a pointer that has not been initialized.

http://www.securityfocus.com/bid/103394
Third Party Advisory
VDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-18-072-01
Third Party Advisory
US Government Resource
Mitigation