Cx Supervisor
Vendor:
First CVE: Mar 21, 2018 · Active for 8 years
20
Total CVEs
More Total CVEs than 95% of tracked products
6.7
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cx Supervisor over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 21, 2018
8 years ago
Most Recent CVE
Oct 19, 2021
1,742 days ago
CVE Severity & Scoring
Cx Supervisor20 CVEs
50%
45%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local17 (85.0%)
Network3 (15.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (35.0%)
Unknown0 (0.0%)
Required13 (65.0%)
Privileges Required
Low12 (60.0%)
High1 (5.0%)
None7 (35.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-18251HIGH In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS. This version of Teamviewer is vulnerable to an obsolete function | Nov 26, 2019 | 8.8 | 27 | NO | NO |
CVE-2018-19017HIGH Several use after free vulnerabilities have been identified in CX-Supervisor (Versions 3.42 and prior). When processing project files, the application fails to check if it is refer | Jan 22, 2019 | 8.8 | 27 | NO | NO |
CVE-2018-19011HIGH CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file. An attacker could exploit this to execute code under the privileges of the appl | Jan 22, 2019 | 8.8 | 27 | NO | NO |
CVE-2018-17913HIGH A type confusion vulnerability exists when processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, which may allow an attacker to execute code in the context of | Nov 5, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-17909HIGH When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, the application fails to check if it is referencing freed memory, which may allow an attacker to ex | Nov 5, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-19015HIGH An attacker could inject commands to launch programs and create, write, and read files on CX-Supervisor (Versions 3.42 and prior) through a specially crafted project file. An attac | Jan 28, 2019 | 7.3 | 24 | NO | NO |
CVE-2018-17905HIGH When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with a specific byte, memory corruption may occur within a specific object. | Nov 5, 2018 | 7.8 | 24 | NO | NO |
CVE-2018-19019HIGH A type confusion vulnerability exists when processing project files in CX-Supervisor (Versions 3.42 and prior). An attacker could use a specially crafted project file to exploit an | Jan 22, 2019 | 7.3 | 23 | NO | NO |
CVE-2021-20836MEDIUM Out-of-bounds read vulnerability in CX-Supervisor v4.0.0.13 and v4.0.0.16 allows an attacker with administrative privileges to cause information disclosure and/or arbitrary code ex | Oct 19, 2021 | 6.5 | 22 | NO | NO |
CVE-2018-19018HIGH An access of uninitialized pointer vulnerability in CX-Supervisor (Versions 3.42 and prior) could lead to type confusion when processing project files. An attacker could use a spec | Feb 12, 2019 | 7.3 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (20 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (20 CVEs).
Media Mentions
Signals from CVEs in this product scope (20 CVEs).
Top CNAs Publishing CVEs For Cx Supervisor
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.0.0.16 | 1 | 6.5 | 0.8% | 0 | 0 |
| 4.0.0.13 | 1 | 6.5 | 0.8% | 0 | 0 |