← Back to home
ICSA-18-100-02  ·  Published 2018-04-10  ·  View on CISA ICS-CERT ↗

Omron CX-One

CVSS 5.3 MEDIUM

Risk Summary

Successful exploitation of these vulnerabilities could allow remote code execution.

Remediations

  • Omron has released an updated version of CX-One to address the reported vulnerabilities. These releases are available through the CX-One auto-update service.
  • CX-FLnet version 1.10,
  • CX-Protocol version 1.993,
  • CX-Programmer versions 9.66,
  • Common Module including CX-Server version 5.0.23,
  • Network Configurator version 3.64, and
  • Switch Box Utility version 1.69

Affected Vendors

Omron

Affected Products (7)

Omron · CX-Protocol <= 1.992
Omron · CX-FLnet <= 1.00
Omron · CX-Programmer <= 9.65
Omron · CX-Server <= 5.0.22
Omron · Switch Box Utility <= 1.68
Omron · Network Configurator <= 3.63
Omron · CX-One <=4.42

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more