CVE-2024-31413

May 1, 2024, 7:50 p.m.

None
No Score

Description

Free of pointer not at start of buffer vulnerability exists in CX-One CX-One CXONE-AL[][]D-V4 (The version which was installed with a DVD ver. 4.61.1 or lower, and was updated through CX-One V4 auto update in January 2024 or prior) and Sysmac Studio SYSMAC-SE2[][][] (The version which was installed with a DVD ver. 1.56 or lower, and was updated through Sysmac Studio V1 auto update in January 2024 or prior). Opening a specially crafted project file may lead to arbitrary code execution.

Product(s) Impacted

Product Versions
CX-One
  • V4.61.1 or lower, updated through CX-One V4 auto update in January 2024 or prior
Sysmac Studio
  • Ver. 1.56 or lower, updated through Sysmac Studio V1 auto update in January 2024 or prior
CX-One
  • V4 (DVD ver. 4.61.1 or lower, updated through CX-One V4 auto update in January 2024 or prior)
Sysmac Studio
  • V1 (DVD ver. 1.56 or lower, updated through Sysmac Studio V1 auto update in January 2024 or prior)

Weaknesses

Common security weaknesses mapped to this vulnerability.

Timeline

Published: May 1, 2024, 1:15 p.m.
Last Modified: May 1, 2024, 7:50 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

vultures@jpcert.or.jp

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.