CVE-2019-18251
OMRON CX-Supervisor Vulnerable Third-Party Component Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS. This version of Teamviewer is vulnerable to an obsolete function vulnerability requiring user interaction to exploit.
En Omron CX-Supervisor, versiones 3.5 (12) y anteriores, Omron CX-Supervisor entregada con Teamviewer versión 5.0.8703 QS. Esta versión de Teamviewer es susceptible a una vulnerabilidad de función obsoleta que requiere la interacción del usuario para explotar.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OMRON CX-Supervisor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within Teamviewer that is installed with Omron CX-Supervisor. The issue results from the use of an outdated version of Teamviewer containing known vulnerabilities. An attacker can leverage this vulnerability to execute code in the context of the current process.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-10-22 CVE Reserved
- 2019-11-25 CVE Published
- 2024-08-05 CVE Updated
- 2024-11-03 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-477: Use of Obsolete Function
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.us-cert.gov/ics/advisories/icsa-19-318-04 | Third Party Advisory | |
https://www.zerodayinitiative.com/advisories/ZDI-19-997 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Omron Search vendor "Omron" | Cx-supervisor Search vendor "Omron" for product "Cx-supervisor" | <= 3.5\(12\) Search vendor "Omron" for product "Cx-supervisor" and version " <= 3.5\(12\)" | - |
Affected
| ||||||
Teamviewer Search vendor "Teamviewer" | Teamviewer Search vendor "Teamviewer" for product "Teamviewer" | 5.0.8703_qs Search vendor "Teamviewer" for product "Teamviewer" and version "5.0.8703_qs" | - |
Affected
|