← Vulnerability feed

Vulnerability record · CVE-2021-27413 · published 13 May 2021

CVE-2021-27413: Omron cx-one stack-based buffer overflow vulnerability

OOmron · Cx One

Omron CX-One Versions 4.60 and prior, including CX-Server Versions 5.0.29.0 and prior, are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.

7.8 CVSS 3.1 High EPSS 10.0% · top 4.5% CWE-121 · Stack-based buffer overflowCWE-787 · Out-of-bounds write
7.8CVSS 3.1 base score, v2 6.8
10.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Omron CX-One Versions 4.60 and prior, including CX-Server Versions 5.0.29.0 and prior, are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://us-cert.cisa.gov/ics/advisories/icsa-21-131-01 Third Party AdvisoryUS Government Resource
https://www.zerodayinitiative.com/advisories/ZDI-21-588/ Third Party AdvisoryVDB Entry
https://us-cert.cisa.gov/ics/advisories/icsa-21-131-01 Third Party AdvisoryUS Government Resource
https://www.zerodayinitiative.com/advisories/ZDI-21-588/ Third Party AdvisoryVDB Entry

Track CVE-2021-27413 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-27259Omron cx-one vulnerabilityThe Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attacker to remot…EPSS 2.7%8.8CVE-2020-27261Omron cx-one stack-based buffer overflow vulnerabilityThe Omron CX-One Version 4.60 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary cod…EPSS 7.6%7.8CVE-2022-21137Omron cx-one stack-based buffer overflow vulnerabilityOmron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processing specific project files, which may allow an atta…EPSS 9.3%7.8CVE-2020-27257Omron cx-one type confusion vulnerabilityThis vulnerability allows local attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can result in a…EPSS 1.8%7.8CVE-2018-19027Omron cx-one type confusion vulnerabilityThree type confusion vulnerabilities exist in CX-One Versions 4.50 and prior and CX-Protocol Versions 2.0 and prior when processing project files. An…EPSS 1.4%7.8CVE-2018-18989Omron cx-one use after free vulnerabilityIn CX-One Versions 4.42 and prior (CX-Programmer Versions 9.66 and prior and CX-Server Versions 5.0.23 and prior), when processing project files, the…EPSS 1.6%7.8CVE-2018-18993Omron cx-one stack-based buffer overflow vulnerabilityTwo stack-based buffer overflow vulnerabilities have been discovered in CX-One Versions 4.42 and prior (CX-Programmer Versions 9.66 and prior and CX-…EPSS 1.8%7.8CVE-2018-7514Omron cx-flnet stack-based buffer overflow vulnerabilityParsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-P…EPSS 0.32%

Source: NIST National Vulnerability Database (record CVE-2021-27413), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.