CVE-2019-18269
Description
Omron CS and CJ series PLCs contain an unrestricted externally accessible lock vulnerability allowing remote attackers to obtain PLC status information without authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Omron CS and CJ series PLCs contain an unrestricted externally accessible lock vulnerability allowing remote attackers to obtain PLC status information without authentication.
Vulnerability
Omron's CS and CJ series PLCs, as well as the NX1P2 series, all versions, are affected by an unrestricted externally accessible lock vulnerability (CWE-412). This flaw allows an attacker to remotely interact with the PLC's lock mechanism without any authentication or special conditions, via the FINS port (default TCP 9600) [1].
Exploitation
An attacker with network access to the PLC can exploit this vulnerability remotely with low skill level. No authentication or user interaction is required. By sending specially crafted packets to the FINS port, the attacker can bypass the lock and gain unauthorized access to the PLC's status information [1].
Impact
Successful exploitation allows an attacker to pose as an authorized user and obtain status information of the PLC. This affects confidentiality and integrity at a low level, but availability at a high level, as reflected in the CVSS v3 base score of 8.6 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H) [1].
Mitigation
Omron recommends mitigating the vulnerability by using a firewall to filter access to the FINS port (default 9600) and blocking unnecessary remote access, as well as filtering IP addresses to restrict which devices can connect to the PLC. No software patch has been released as of the advisory date. CISA additionally recommends defensive measures to minimize risk [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4(expand)+ 1 more
- (no CPE)
- (no CPE)range: all versions
- Omron/Omron PLC CS seriesv5Range: all versions
- Omron/Omron PLC NX1P2 seriesv5Range: all versions
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
2- www.us-cert.gov/ics/advisories/icsa-19-346-02nvdThird Party AdvisoryUS Government Resource
- www.omron-cxone.com/security/2019-12-06_PLC_EN.pdfnvd
News mentions
0No linked articles in our index yet.