5.3

CVE-2018-7515

In Omron CX-Supervisor Versions 3.30 and prior, access of uninitialized pointer vulnerabilities can be exploited when CX Supervisor indirectly calls an initialized pointer when parsing malformed packets.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OmronCx-supervisor Version <= 3.30
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.22
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 1.8 3.4
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
NIST 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-256 Plaintext Storage of a Password

The product stores a password in plaintext within resources such as memory or files.

CWE-824 Access of Uninitialized Pointer

The product accesses or uses a pointer that has not been initialized.

http://www.securityfocus.com/bid/103394
Third Party Advisory
VDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-18-072-01
Third Party Advisory
US Government Resource
Mitigation