CVE-2018-19011 is a critical code injection vulnerability affecting Omron CX-Supervisor versions 3.42 and prior. An unauthenticated attacker can exploit this flaw by injecting malicious code into a project file, which the application will then execute with its privileges. This vulnerability carries a high CVSS score of 8.8, indicating a severe risk of complete compromise of confidentiality, integrity, and availability. While no public exploits, Metasploit modules, or community discussions are currently identified, the potential for remote code execution makes it a significant threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.42CPE matchmatch criteria | cpe:2.3:a:omron:cx-supervisor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.