Skip to content
Noroxi

Omron records

91 published records for vendor omron.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
9
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

91 records
  • Buffer overflow in SGI Omron WorldView Wnn allows remote attackers to execute arbitrary commands via long JS_OPEN, JS_MKDIR, or JS_FILE_INFO

    CriticalCVSS 10.0Proof of conceptEPSS 13%

    omron · worldviewOct 20, 2000

  • In Omron PLC CJ series, all versions and Omron PLC CS series, all versions, an attacker could spoof arbitrary messages or execute commands.

    CriticalCVSS 9.8No exploitEPSS 2%

    omron · plc cj firmwareDec 16, 2019

  • Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission,

    CriticalCVSS 10.0No exploitEPSS 1%

    omron · cx-programmerOct 5, 2015

  • CVE-2018-6624
    39Monitor

    OMRON NS devices 1.1 through 1.3 allow remote attackers to bypass authentication via a direct request to the .html file for a specific scree

    CriticalCVSS 9.8No exploitEPSS 2%

    omron · ns series firmwareFeb 5, 2018

  • FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation)

    CriticalCVSS 9.8No exploitEPSS 1%

    omron · cs1w-eip21 firmwareJun 19, 2023

  • In Omron PLC CS series, all versions, Omron PLC CJ series, all versions, and Omron PLC NJ series, all versions, the software does not implem

    CriticalCVSS 9.8No exploitEPSS 1%

    omron · plc cj firmwareDec 16, 2019

  • Active debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS protocol being execu

    CriticalCVSS 9.8No exploitEPSS 1%

    omron · cp1l-el20dr-d firmwareJan 17, 2023

  • The Omron SYSMAC Nx product family PLCs (NJ series, NY series, NX series, and PMAC series) through 2022-005-18 lack cryptographic authentica

    CriticalCVSS 9.8No exploitEPSS 1%

    omron · nx701-1600 firmwareJul 26, 2022

  • Omron’s CS and CJ series PLCs have an unrestricted externally accessible lock vulnerability.

    CriticalCVSS 9.8No exploitEPSS 1%

    omron · plc cj firmwareDec 16, 2019

  • The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic authentication.

    CriticalCVSS 9.8No exploitEPSS 1%

    omron · sysmac cs1 firmwareJul 26, 2022

  • CVE-2022-3396
    39Monitor

    OMRON CX-Programmer Out-of-bounds Write

    CriticalCVSS 9.8No exploitEPSS 1%

    omron · cx-programmerOct 6, 2022

  • CVE-2022-3398
    39Monitor

    OMRON CX-Programmer Out-of-bounds Write

    CriticalCVSS 9.8No exploitEPSS 1%

    omron · cx-programmerOct 6, 2022

  • CVE-2022-3397
    39Monitor

    OMRON CX-Programmer Out-of-bounds Write

    CriticalCVSS 9.8No exploitEPSS 1%

    omron · cx-programmerOct 6, 2022

  • The Omron CX-One Version 4.60 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbi

    HighCVSS 8.8No exploitEPSS 8%

    omron · cx-oneFeb 9, 2021

  • The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attacker

    HighCVSS 8.8No exploitEPSS 3%

    omron · cx-oneFeb 9, 2021

  • CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file.

    HighCVSS 8.8No exploitEPSS 2%

    omron · cx-supervisorJan 22, 2019

  • Several use after free vulnerabilities have been identified in CX-Supervisor (Versions 3.42 and prior).

    HighCVSS 8.8No exploitEPSS 2%

    omron · cx-supervisorJan 22, 2019

  • In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS.

    HighCVSS 8.8No exploitEPSS 2%

    omron · cx-supervisorNov 25, 2019

  • Omron FINS memory protection susceptible to bruteforce

    CriticalCVSS 9.1No exploitEPSS 1%

    omron · cj1g-cpu45p firmwareJan 22, 2024

  • CVE-2023-0811
    36Monitor

    Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored.

    CriticalCVSS 9.1No exploitEPSS 1%

    omron · sysmac cj2h-cpu64 firmwareMar 16, 2023

  • Omron CX-One Versions 4.60 and prior, including CX-Server Versions 5.0.29.0 and prior, are vulnerable to a stack-based buffer overflow, whic

    HighCVSS 7.8No exploitEPSS 10%

    omron · cx-oneMay 13, 2021

  • Omron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processing specific project files, which may allo

    HighCVSS 7.8No exploitEPSS 9%

    omron · cx-oneJan 14, 2022

  • Authentication bypass by capture-replay vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machi

    HighCVSS 8.1No exploitEPSS 2%

    omron · nx701-1600 firmwareJul 3, 2022

  • Rockwell Automation Studio 5000 Logix Designer Code Injection

    HighCVSS 7.8No exploitEPSS 2%

    omron · cx-positionApr 1, 2022

  • This vulnerability allows local attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can re

    HighCVSS 7.8No exploitEPSS 2%

    omron · cx-oneFeb 9, 2021