This vulnerability allows local attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can result in a type-confusion condition in the Omron CX-One Version 4.60 and prior devices.
References
Link Resource
https://us-cert.cisa.gov/ics/advisories/icsa-21-007-02 Third Party Advisory US Government Resource
https://www.zerodayinitiative.com/advisories/ZDI-21-184/ Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: icscert

Published: 2021-01-07T00:00:00

Updated: 2021-02-10T18:06:13

Reserved: 2020-10-19T00:00:00


Link: CVE-2020-27257

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-02-09T15:15:12.970

Modified: 2021-02-12T17:51:25.970


Link: CVE-2020-27257

JSON object: View

cve-icon Redhat Information

No data.

CWE