Omron records
91 published records for vendor omron.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 9
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-416 Use After Free15
- CWE-787 Out-of-bounds Write11
- CWE-121 Stack-based Buffer Overflow7
- CWE-125 Out-of-bounds Read5
- CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
The weakness classes this vendor ships most often: where to look.
CWEAll records
91 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
44Plan | CVE-2000-0704Proof of concept | Buffer overflow in SGI Omron WorldView Wnn allows remote attackers to execute arbitrary commands via long JS_OPEN, JS_MKDIR, or JS_FILE_INFOomron · worldview | Critical10.0 | — | 13.1% | Oct 20, 2000 |
40Plan | CVE-2019-18259No exploit | In Omron PLC CJ series, all versions and Omron PLC CS series, all versions, an attacker could spoof arbitrary messages or execute commands.omron · plc cj firmware · CWE-290 | Critical9.8 | — | 2.1% | Dec 16, 2019 |
40Plan | CVE-2015-0987No exploit | Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission,omron · cx-programmer · CWE-200 | Critical10.0 | — | 1.2% | Oct 5, 2015 |
39Monitor | CVE-2018-6624No exploit | OMRON NS devices 1.1 through 1.3 allow remote attackers to bypass authentication via a direct request to the .html file for a specific screeomron · ns series firmware · CWE-425 | Critical9.8 | — | 1.6% | Feb 5, 2018 |
39Monitor | CVE-2023-27396No exploit | FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation)omron · cs1w-eip21 firmware · CWE-306 | Critical9.8 | — | 1.4% | Jun 19, 2023 |
39Monitor | CVE-2019-18261No exploit | In Omron PLC CS series, all versions, Omron PLC CJ series, all versions, and Omron PLC NJ series, all versions, the software does not implemomron · plc cj firmware · CWE-307 | Critical9.8 | — | 1.3% | Dec 16, 2019 |
39Monitor | CVE-2023-22357No exploit | Active debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS protocol being execuomron · cp1l-el20dr-d firmware · CWE-489 | Critical9.8 | — | 1.2% | Jan 17, 2023 |
39Monitor | CVE-2022-31206No exploit | The Omron SYSMAC Nx product family PLCs (NJ series, NY series, NX series, and PMAC series) through 2022-005-18 lack cryptographic authenticaomron · nx701-1600 firmware · CWE-347 | Critical9.8 | — | 1.1% | Jul 26, 2022 |
39Monitor | CVE-2019-18269No exploit | Omron’s CS and CJ series PLCs have an unrestricted externally accessible lock vulnerability.omron · plc cj firmware · CWE-412 | Critical9.8 | — | 1.0% | Dec 16, 2019 |
39Monitor | CVE-2022-31207No exploit | The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic authentication.omron · sysmac cs1 firmware · CWE-347 | Critical9.8 | — | 1.0% | Jul 26, 2022 |
39Monitor | CVE-2022-3396No exploit | OMRON CX-Programmer Out-of-bounds Writeomron · cx-programmer · CWE-787 | Critical9.8 | — | 0.6% | Oct 6, 2022 |
39Monitor | CVE-2022-3398No exploit | OMRON CX-Programmer Out-of-bounds Writeomron · cx-programmer · CWE-787 | Critical9.8 | — | 0.6% | Oct 6, 2022 |
39Monitor | CVE-2022-3397No exploit | OMRON CX-Programmer Out-of-bounds Writeomron · cx-programmer · CWE-787 | Critical9.8 | — | 0.6% | Oct 6, 2022 |
37Monitor | CVE-2020-27261No exploit | The Omron CX-One Version 4.60 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbiomron · cx-one · CWE-121 | High8.8 | — | 7.6% | Feb 9, 2021 |
36Monitor | CVE-2020-27259No exploit | The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attackeromron · cx-one · CWE-822 | High8.8 | — | 2.7% | Feb 9, 2021 |
36Monitor | CVE-2018-19011No exploit | CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file.omron · cx-supervisor · CWE-94 | High8.8 | — | 2.4% | Jan 22, 2019 |
36Monitor | CVE-2018-19017No exploit | Several use after free vulnerabilities have been identified in CX-Supervisor (Versions 3.42 and prior).omron · cx-supervisor · CWE-416 | High8.8 | — | 2.4% | Jan 22, 2019 |
36Monitor | CVE-2019-18251No exploit | In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS.omron · cx-supervisor · CWE-477 | High8.8 | — | 1.7% | Nov 25, 2019 |
36Monitor | CVE-2022-45790No exploit | Omron FINS memory protection susceptible to bruteforceomron · cj1g-cpu45p firmware · CWE-307 | Critical9.1 | — | 0.9% | Jan 22, 2024 |
36Monitor | CVE-2023-0811No exploit | Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored.omron · sysmac cj2h-cpu64 firmware · CWE-284 | Critical9.1 | — | 0.6% | Mar 16, 2023 |
34Monitor | CVE-2021-27413No exploit | Omron CX-One Versions 4.60 and prior, including CX-Server Versions 5.0.29.0 and prior, are vulnerable to a stack-based buffer overflow, whicomron · cx-one · CWE-121 | High7.8 | — | 10.0% | May 13, 2021 |
34Monitor | CVE-2022-21137No exploit | Omron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processing specific project files, which may alloomron · cx-one · CWE-121 | High7.8 | — | 9.3% | Jan 14, 2022 |
33Monitor | CVE-2022-33208No exploit | Authentication bypass by capture-replay vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machiomron · nx701-1600 firmware · CWE-294 | High8.1 | — | 1.9% | Jul 3, 2022 |
32Monitor | CVE-2022-26419No exploit | Rockwell Automation Studio 5000 Logix Designer Code Injectionomron · cx-position · CWE-121 | High7.8 | — | 2.1% | Apr 1, 2022 |
32Monitor | CVE-2020-27257No exploit | This vulnerability allows local attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can reomron · cx-one · CWE-843 | High7.8 | — | 1.8% | Feb 9, 2021 |
- CVE-2000-070444Plan
Buffer overflow in SGI Omron WorldView Wnn allows remote attackers to execute arbitrary commands via long JS_OPEN, JS_MKDIR, or JS_FILE_INFO
CriticalCVSS 10.0Proof of conceptEPSS 13%omron · worldviewOct 20, 2000
- CVE-2019-1825940Plan
In Omron PLC CJ series, all versions and Omron PLC CS series, all versions, an attacker could spoof arbitrary messages or execute commands.
CriticalCVSS 9.8No exploitEPSS 2%omron · plc cj firmwareDec 16, 2019
- CVE-2015-098740Plan
Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission,
CriticalCVSS 10.0No exploitEPSS 1%omron · cx-programmerOct 5, 2015
- CVE-2018-662439Monitor
OMRON NS devices 1.1 through 1.3 allow remote attackers to bypass authentication via a direct request to the .html file for a specific scree
CriticalCVSS 9.8No exploitEPSS 2%omron · ns series firmwareFeb 5, 2018
- CVE-2023-2739639Monitor
FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation)
CriticalCVSS 9.8No exploitEPSS 1%omron · cs1w-eip21 firmwareJun 19, 2023
- CVE-2019-1826139Monitor
In Omron PLC CS series, all versions, Omron PLC CJ series, all versions, and Omron PLC NJ series, all versions, the software does not implem
CriticalCVSS 9.8No exploitEPSS 1%omron · plc cj firmwareDec 16, 2019
- CVE-2023-2235739Monitor
Active debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS protocol being execu
CriticalCVSS 9.8No exploitEPSS 1%omron · cp1l-el20dr-d firmwareJan 17, 2023
- CVE-2022-3120639Monitor
The Omron SYSMAC Nx product family PLCs (NJ series, NY series, NX series, and PMAC series) through 2022-005-18 lack cryptographic authentica
CriticalCVSS 9.8No exploitEPSS 1%omron · nx701-1600 firmwareJul 26, 2022
- CVE-2019-1826939Monitor
Omron’s CS and CJ series PLCs have an unrestricted externally accessible lock vulnerability.
CriticalCVSS 9.8No exploitEPSS 1%omron · plc cj firmwareDec 16, 2019
- CVE-2022-3120739Monitor
The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic authentication.
CriticalCVSS 9.8No exploitEPSS 1%omron · sysmac cs1 firmwareJul 26, 2022
- CVE-2022-339639Monitor
OMRON CX-Programmer Out-of-bounds Write
CriticalCVSS 9.8No exploitEPSS 1%omron · cx-programmerOct 6, 2022
- CVE-2022-339839Monitor
OMRON CX-Programmer Out-of-bounds Write
CriticalCVSS 9.8No exploitEPSS 1%omron · cx-programmerOct 6, 2022
- CVE-2022-339739Monitor
OMRON CX-Programmer Out-of-bounds Write
CriticalCVSS 9.8No exploitEPSS 1%omron · cx-programmerOct 6, 2022
- CVE-2020-2726137Monitor
The Omron CX-One Version 4.60 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbi
HighCVSS 8.8No exploitEPSS 8%omron · cx-oneFeb 9, 2021
- CVE-2020-2725936Monitor
The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attacker
HighCVSS 8.8No exploitEPSS 3%omron · cx-oneFeb 9, 2021
- CVE-2018-1901136Monitor
CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file.
HighCVSS 8.8No exploitEPSS 2%omron · cx-supervisorJan 22, 2019
- CVE-2018-1901736Monitor
Several use after free vulnerabilities have been identified in CX-Supervisor (Versions 3.42 and prior).
HighCVSS 8.8No exploitEPSS 2%omron · cx-supervisorJan 22, 2019
- CVE-2019-1825136Monitor
In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS.
HighCVSS 8.8No exploitEPSS 2%omron · cx-supervisorNov 25, 2019
- CVE-2022-4579036Monitor
Omron FINS memory protection susceptible to bruteforce
CriticalCVSS 9.1No exploitEPSS 1%omron · cj1g-cpu45p firmwareJan 22, 2024
- CVE-2023-081136Monitor
Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored.
CriticalCVSS 9.1No exploitEPSS 1%omron · sysmac cj2h-cpu64 firmwareMar 16, 2023
- CVE-2021-2741334Monitor
Omron CX-One Versions 4.60 and prior, including CX-Server Versions 5.0.29.0 and prior, are vulnerable to a stack-based buffer overflow, whic
HighCVSS 7.8No exploitEPSS 10%omron · cx-oneMay 13, 2021
- CVE-2022-2113734Monitor
Omron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processing specific project files, which may allo
HighCVSS 7.8No exploitEPSS 9%omron · cx-oneJan 14, 2022
- CVE-2022-3320833Monitor
Authentication bypass by capture-replay vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machi
HighCVSS 8.1No exploitEPSS 2%omron · nx701-1600 firmwareJul 3, 2022
- CVE-2022-2641932Monitor
Rockwell Automation Studio 5000 Logix Designer Code Injection
HighCVSS 7.8No exploitEPSS 2%omron · cx-positionApr 1, 2022
- CVE-2020-2725732Monitor
This vulnerability allows local attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can re
HighCVSS 7.8No exploitEPSS 2%omron · cx-oneFeb 9, 2021