VYPR

Vendor CVEs

Omron

All CVEs

98 total · sorted by risk
  • CVE-2015-0987CriOct 6, 2015
    risk 0.65cvss 10.0epss 0.01

    Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission, which allows remote attackers to obtain sensitive information by sniffing the network during a PLC unlock request.

  • CVE-2023-27396CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation) networks, and is used in FA networks composed of OMRON products. Multiple OMRON products that implement FINS protocol contain following…

  • CVE-2023-22357CriJan 17, 2023
    risk 0.64cvss 9.8epss 0.01

    Active debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS protocol being executed without authentication. A remote unauthenticated attacker may read/write in arbitrary area of the device memory, which may lead to…

  • CVE-2022-31207CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic authentication. They utilize the Omron FINS (9600/TCP) protocol for engineering purposes, including downloading projects and control logic to the PLC. This…

  • CVE-2022-31206CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    The Omron SYSMAC Nx product family PLCs (NJ series, NY series, NX series, and PMAC series) through 2022-005-18 lack cryptographic authentication. These PLCs are programmed using the SYMAC Studio engineering software (which compiles IEC 61131-3 conformant POU code to native…

  • CVE-2019-18269CriDec 16, 2019
    risk 0.64cvss 9.8epss 0.01

    Omron’s CS and CJ series PLCs have an unrestricted externally accessible lock vulnerability.

  • CVE-2019-18261CriDec 16, 2019
    risk 0.64cvss 9.8epss 0.01

    In Omron PLC CS series, all versions, Omron PLC CJ series, all versions, and Omron PLC NJ series, all versions, the software does not implement sufficient measures to prevent multiple failed authentication attempts within in a short time frame, making it more susceptible to…

  • CVE-2019-18259CriDec 16, 2019
    risk 0.64cvss 9.8epss 0.02

    In Omron PLC CJ series, all versions and Omron PLC CS series, all versions, an attacker could spoof arbitrary messages or execute commands.

  • CVE-2018-6624CriFeb 5, 2018
    risk 0.64cvss 9.8epss 0.02

    OMRON NS devices 1.1 through 1.3 allow remote attackers to bypass authentication via a direct request to the .html file for a specific screen, as demonstrated by monitor.html.

  • CVE-2023-0811CriMar 16, 2023
    risk 0.59cvss 9.1epss 0.01

    Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an adversary issues a PROGRAM AREA WRITE command to a specific memory region, they could overwrite the password. This may lead to disabling UM protections or…

  • CVE-2020-27261HigFeb 9, 2021
    risk 0.58cvss 8.8epss 0.08

    The Omron CX-One Version 4.60 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2020-27259HigFeb 9, 2021
    risk 0.57cvss 8.8epss 0.03

    The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2019-18251HigNov 26, 2019
    risk 0.57cvss 8.8epss 0.02

    In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS. This version of Teamviewer is vulnerable to an obsolete function vulnerability requiring user interaction to exploit.

  • CVE-2018-19017HigJan 22, 2019
    risk 0.57cvss 8.8epss 0.02

    Several use after free vulnerabilities have been identified in CX-Supervisor (Versions 3.42 and prior). When processing project files, the application fails to check if it is referencing freed memory. An attacker could use a specially crafted project file to exploit and execute…

  • CVE-2018-19011HigJan 22, 2019
    risk 0.57cvss 8.8epss 0.02

    CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file. An attacker could exploit this to execute code under the privileges of the application.

  • CVE-2022-45790HigJan 22, 2024
    risk 0.56cvss 8.6epss 0.01

    The Omron FINS protocol has an authenticated feature to prevent access to memory regions. Authentication is susceptible to bruteforce attack, which may allow an adversary to gain access to protected memory. This access can allow overwrite of values including programmed logic.

  • CVE-2022-45794HigJan 10, 2024
    risk 0.56cvss 8.6epss 0.01

    An attacker with network access to the affected PLC (CJ-series and CS-series PLCs, all versions) may use a network protocol to read and write files on the PLC internal memory and memory card.

  • CVE-2022-34151HigJul 4, 2022
    risk 0.53cvss 8.1epss 0.01

    Use of hard-coded credentials vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, Automation…

  • CVE-2022-33208HigJul 4, 2022
    risk 0.53cvss 8.1epss 0.02

    Authentication bypass by capture-replay vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier,…

  • CVE-2019-13533HigDec 16, 2019
    risk 0.53cvss 8.1epss 0.01

    In Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monitor traffic between the PLC and the controller and replay requests that could result in the opening and closing of industrial valves.

  • CVE-2026-5397HigApr 15, 2026
    risk 0.51cvss 7.8epss 0.00

    It has been identified that a vulnerability (CWE-427) exists in the UPS (Uninterruptible Power Supply) management application, whereby improper permissions on the installation directory allow a malicious actor to place a DLL that is then executed with administrator privileges. …

  • CVE-2025-0591HigFeb 17, 2025
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds Read vulnerability (CWE-125) was found in CX-Programmer. Attackers may be able to read sensitive information or cause an application crash by abusing this vulnerability.

  • CVE-2024-31412HigMay 1, 2024
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read vulnerability exists in CX-Programmer included in CX-One CXONE-AL[][]D-V4 Ver. 9.81 or lower. Opening a specially crafted project file may lead to information disclosure and/or the product being crashed.

  • CVE-2022-45792HigJan 22, 2024
    risk 0.51cvss 7.8epss 0.00

    Project files may contain malicious contents which the software will use to create files on the filesystem. This allows directory traversal and overwriting files with the privileges of the logged-in user.

  • CVE-2023-22277HigAug 3, 2023
    risk 0.51cvss 7.8epss 0.00

    Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22317 and CVE-2023-22314.

  • CVE-2023-22317HigAug 3, 2023
    risk 0.51cvss 7.8epss 0.00

    Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22277 and CVE-2023-22314.

  • CVE-2023-22314HigAug 3, 2023
    risk 0.51cvss 7.8epss 0.00

    Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22277 and CVE-2023-22317.

  • CVE-2023-38748HigAug 3, 2023
    risk 0.51cvss 7.8epss 0.00

    Use after free vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur.

  • CVE-2023-38747HigAug 3, 2023
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur.

  • CVE-2023-38746HigAug 3, 2023
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read vulnerability/issue exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur.

  • CVE-2023-27385HigMay 10, 2023
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow vulnerability exists in CX-Drive All models all versions. By having a user open a specially crafted SDD file, arbitrary code may be executed and/or information may be disclosed.

  • CVE-2023-22366HigJan 17, 2023
    risk 0.51cvss 7.8epss 0.00

    CX-Motion-MCH v2.32 and earlier contains an access of uninitialized pointer vulnerability. Having a user to open a specially crafted project file may lead to information disclosure and/or arbitrary code execution.

  • CVE-2022-46282HigDec 21, 2022
    risk 0.51cvss 7.8epss 0.00

    Use after free vulnerability in CX-Drive V3.00 and earlier allows a local attacker to execute arbitrary code by having a user to open a specially crafted file,

  • CVE-2022-43667HigDec 7, 2022
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.

  • CVE-2022-43509HigDec 7, 2022
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds write vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.

  • CVE-2022-43508HigDec 7, 2022
    risk 0.51cvss 7.8epss 0.00

    Use-after free vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.

  • CVE-2022-3398HigOct 6, 2022
    risk 0.51cvss 7.8epss 0.01

    OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code.

  • CVE-2022-3397HigOct 6, 2022
    risk 0.51cvss 7.8epss 0.01

    OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code.

  • CVE-2022-3396HigOct 6, 2022
    risk 0.51cvss 7.8epss 0.01

    OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code.

  • CVE-2022-2979HigSep 12, 2022
    risk 0.51cvss 7.8epss 0.00

    Opening a specially crafted file could cause the affected product to fail to release its memory reference potentially resulting in arbitrary code execution.

  • CVE-2022-26419HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.02

    Omron CX-Position (versions 2.5.3 and prior) is vulnerable to multiple stack-based buffer overflow conditions while parsing a specific project file, which may allow an attacker to locally execute arbitrary code.

  • CVE-2022-26417HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.01

    Omron CX-Position (versions 2.5.3 and prior) is vulnerable to a use after free memory condition while processing a specific project file, which may allow an attacker to execute arbitrary code.

  • CVE-2022-26022HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.01

    Omron CX-Position (versions 2.5.3 and prior) is vulnerable to an out-of-bounds write while processing a specific project file, which may allow an attacker to execute arbitrary code.

  • CVE-2022-25959HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.01

    Omron CX-Position (versions 2.5.3 and prior) is vulnerable to memory corruption while processing a specific project file, which may allow an attacker to execute arbitrary code.

  • CVE-2022-25325HigMar 10, 2022
    risk 0.51cvss 7.8epss 0.01

    Use after free vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. This vulnerability is different…

  • CVE-2022-25234HigMar 10, 2022
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds write vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. This vulnerability is…

  • CVE-2022-25230HigMar 10, 2022
    risk 0.51cvss 7.8epss 0.01

    Use after free vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. This vulnerability is different…

  • CVE-2022-21219HigMar 10, 2022
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.

  • CVE-2022-21124HigMar 10, 2022
    risk 0.51cvss 7.8epss 0.02

    Out-of-bounds write vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. This vulnerability is…

  • CVE-2022-21137HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.09

    Omron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processing specific project files, which may allow an attacker to execute arbitrary code.

Page 1 of 2