5.3
CVE-2018-7515
- EPSS 0.07%
- Published 21.03.2018 20:29:01
- Last modified 21.11.2024 04:12:16
- Source ics-cert@hq.dhs.gov
- Teams watchlist Login
- Open Login
In Omron CX-Supervisor Versions 3.30 and prior, access of uninitialized pointer vulnerabilities can be exploited when CX Supervisor indirectly calls an initialized pointer when parsing malformed packets.
Data is provided by the National Vulnerability Database (NVD)
Omron ≫ Cx-supervisor Version <= 3.30
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.07% | 0.172 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.3 | 1.8 | 3.4 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
|
nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
CWE-256 Plaintext Storage of a Password
Storing a password in plaintext may result in a system compromise.
CWE-824 Access of Uninitialized Pointer
The product accesses or uses a pointer that has not been initialized.