Записи Omron
91 опубликованных записей вендора omron.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 9
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-416 Use After Free15
- CWE-787 Out-of-bounds Write11
- CWE-121 Stack-based Buffer Overflow7
- CWE-125 Out-of-bounds Read5
- CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
91 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
44В плане | CVE-2000-0704Proof of concept | Buffer overflow in SGI Omron WorldView Wnn allows remote attackers to execute arbitrary commands via long JS_OPEN, JS_MKDIR, or JS_FILE_INFOomron · worldview | Критическая10,0 | — | 13,1 % | 20 окт. 2000 г. |
40В плане | CVE-2019-18259Эксплойта нет | In Omron PLC CJ series, all versions and Omron PLC CS series, all versions, an attacker could spoof arbitrary messages or execute commands.omron · plc cj firmware · CWE-290 | Критическая9,8 | — | 2,1 % | 16 дек. 2019 г. |
40В плане | CVE-2015-0987Эксплойта нет | Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission,omron · cx-programmer · CWE-200 | Критическая10,0 | — | 1,2 % | 5 окт. 2015 г. |
39Наблюдать | CVE-2018-6624Эксплойта нет | OMRON NS devices 1.1 through 1.3 allow remote attackers to bypass authentication via a direct request to the .html file for a specific screeomron · ns series firmware · CWE-425 | Критическая9,8 | — | 1,6 % | 5 февр. 2018 г. |
39Наблюдать | CVE-2023-27396Эксплойта нет | FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation)omron · cs1w-eip21 firmware · CWE-306 | Критическая9,8 | — | 1,4 % | 19 июн. 2023 г. |
39Наблюдать | CVE-2019-18261Эксплойта нет | In Omron PLC CS series, all versions, Omron PLC CJ series, all versions, and Omron PLC NJ series, all versions, the software does not implemomron · plc cj firmware · CWE-307 | Критическая9,8 | — | 1,3 % | 16 дек. 2019 г. |
39Наблюдать | CVE-2023-22357Эксплойта нет | Active debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS protocol being execuomron · cp1l-el20dr-d firmware · CWE-489 | Критическая9,8 | — | 1,2 % | 17 янв. 2023 г. |
39Наблюдать | CVE-2022-31206Эксплойта нет | The Omron SYSMAC Nx product family PLCs (NJ series, NY series, NX series, and PMAC series) through 2022-005-18 lack cryptographic authenticaomron · nx701-1600 firmware · CWE-347 | Критическая9,8 | — | 1,1 % | 26 июл. 2022 г. |
39Наблюдать | CVE-2019-18269Эксплойта нет | Omron’s CS and CJ series PLCs have an unrestricted externally accessible lock vulnerability.omron · plc cj firmware · CWE-412 | Критическая9,8 | — | 1,0 % | 16 дек. 2019 г. |
39Наблюдать | CVE-2022-31207Эксплойта нет | The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic authentication.omron · sysmac cs1 firmware · CWE-347 | Критическая9,8 | — | 1,0 % | 26 июл. 2022 г. |
39Наблюдать | CVE-2022-3396Эксплойта нет | OMRON CX-Programmer Out-of-bounds Writeomron · cx-programmer · CWE-787 | Критическая9,8 | — | 0,6 % | 6 окт. 2022 г. |
39Наблюдать | CVE-2022-3398Эксплойта нет | OMRON CX-Programmer Out-of-bounds Writeomron · cx-programmer · CWE-787 | Критическая9,8 | — | 0,6 % | 6 окт. 2022 г. |
39Наблюдать | CVE-2022-3397Эксплойта нет | OMRON CX-Programmer Out-of-bounds Writeomron · cx-programmer · CWE-787 | Критическая9,8 | — | 0,6 % | 6 окт. 2022 г. |
37Наблюдать | CVE-2020-27261Эксплойта нет | The Omron CX-One Version 4.60 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbiomron · cx-one · CWE-121 | Высокая8,8 | — | 7,6 % | 9 февр. 2021 г. |
36Наблюдать | CVE-2020-27259Эксплойта нет | The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attackeromron · cx-one · CWE-822 | Высокая8,8 | — | 2,7 % | 9 февр. 2021 г. |
36Наблюдать | CVE-2018-19011Эксплойта нет | CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file.omron · cx-supervisor · CWE-94 | Высокая8,8 | — | 2,4 % | 22 янв. 2019 г. |
36Наблюдать | CVE-2018-19017Эксплойта нет | Several use after free vulnerabilities have been identified in CX-Supervisor (Versions 3.42 and prior).omron · cx-supervisor · CWE-416 | Высокая8,8 | — | 2,4 % | 22 янв. 2019 г. |
36Наблюдать | CVE-2019-18251Эксплойта нет | In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS.omron · cx-supervisor · CWE-477 | Высокая8,8 | — | 1,7 % | 25 нояб. 2019 г. |
36Наблюдать | CVE-2022-45790Эксплойта нет | Omron FINS memory protection susceptible to bruteforceomron · cj1g-cpu45p firmware · CWE-307 | Критическая9,1 | — | 0,9 % | 22 янв. 2024 г. |
36Наблюдать | CVE-2023-0811Эксплойта нет | Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored.omron · sysmac cj2h-cpu64 firmware · CWE-284 | Критическая9,1 | — | 0,6 % | 16 мар. 2023 г. |
34Наблюдать | CVE-2021-27413Эксплойта нет | Omron CX-One Versions 4.60 and prior, including CX-Server Versions 5.0.29.0 and prior, are vulnerable to a stack-based buffer overflow, whicomron · cx-one · CWE-121 | Высокая7,8 | — | 10,0 % | 13 мая 2021 г. |
34Наблюдать | CVE-2022-21137Эксплойта нет | Omron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processing specific project files, which may alloomron · cx-one · CWE-121 | Высокая7,8 | — | 9,3 % | 14 янв. 2022 г. |
33Наблюдать | CVE-2022-33208Эксплойта нет | Authentication bypass by capture-replay vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machiomron · nx701-1600 firmware · CWE-294 | Высокая8,1 | — | 1,9 % | 3 июл. 2022 г. |
32Наблюдать | CVE-2022-26419Эксплойта нет | Rockwell Automation Studio 5000 Logix Designer Code Injectionomron · cx-position · CWE-121 | Высокая7,8 | — | 2,1 % | 1 апр. 2022 г. |
32Наблюдать | CVE-2020-27257Эксплойта нет | This vulnerability allows local attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can reomron · cx-one · CWE-843 | Высокая7,8 | — | 1,8 % | 9 февр. 2021 г. |
- CVE-2000-070444В плане
Buffer overflow in SGI Omron WorldView Wnn allows remote attackers to execute arbitrary commands via long JS_OPEN, JS_MKDIR, or JS_FILE_INFO
КритическаяCVSS 10,0Proof of conceptEPSS 13 %omron · worldview20 окт. 2000 г.
- CVE-2019-1825940В плане
In Omron PLC CJ series, all versions and Omron PLC CS series, all versions, an attacker could spoof arbitrary messages or execute commands.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %omron · plc cj firmware16 дек. 2019 г.
- CVE-2015-098740В плане
Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission,
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %omron · cx-programmer5 окт. 2015 г.
- CVE-2018-662439Наблюдать
OMRON NS devices 1.1 through 1.3 allow remote attackers to bypass authentication via a direct request to the .html file for a specific scree
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %omron · ns series firmware5 февр. 2018 г.
- CVE-2023-2739639Наблюдать
FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation)
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %omron · cs1w-eip21 firmware19 июн. 2023 г.
- CVE-2019-1826139Наблюдать
In Omron PLC CS series, all versions, Omron PLC CJ series, all versions, and Omron PLC NJ series, all versions, the software does not implem
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %omron · plc cj firmware16 дек. 2019 г.
- CVE-2023-2235739Наблюдать
Active debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS protocol being execu
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %omron · cp1l-el20dr-d firmware17 янв. 2023 г.
- CVE-2022-3120639Наблюдать
The Omron SYSMAC Nx product family PLCs (NJ series, NY series, NX series, and PMAC series) through 2022-005-18 lack cryptographic authentica
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %omron · nx701-1600 firmware26 июл. 2022 г.
- CVE-2019-1826939Наблюдать
Omron’s CS and CJ series PLCs have an unrestricted externally accessible lock vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %omron · plc cj firmware16 дек. 2019 г.
- CVE-2022-3120739Наблюдать
The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic authentication.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %omron · sysmac cs1 firmware26 июл. 2022 г.
- CVE-2022-339639Наблюдать
OMRON CX-Programmer Out-of-bounds Write
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %omron · cx-programmer6 окт. 2022 г.
- CVE-2022-339839Наблюдать
OMRON CX-Programmer Out-of-bounds Write
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %omron · cx-programmer6 окт. 2022 г.
- CVE-2022-339739Наблюдать
OMRON CX-Programmer Out-of-bounds Write
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %omron · cx-programmer6 окт. 2022 г.
- CVE-2020-2726137Наблюдать
The Omron CX-One Version 4.60 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbi
ВысокаяCVSS 8,8Эксплойта нетEPSS 8 %omron · cx-one9 февр. 2021 г.
- CVE-2020-2725936Наблюдать
The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attacker
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %omron · cx-one9 февр. 2021 г.
- CVE-2018-1901136Наблюдать
CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %omron · cx-supervisor22 янв. 2019 г.
- CVE-2018-1901736Наблюдать
Several use after free vulnerabilities have been identified in CX-Supervisor (Versions 3.42 and prior).
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %omron · cx-supervisor22 янв. 2019 г.
- CVE-2019-1825136Наблюдать
In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %omron · cx-supervisor25 нояб. 2019 г.
- CVE-2022-4579036Наблюдать
Omron FINS memory protection susceptible to bruteforce
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %omron · cj1g-cpu45p firmware22 янв. 2024 г.
- CVE-2023-081136Наблюдать
Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %omron · sysmac cj2h-cpu64 firmware16 мар. 2023 г.
- CVE-2021-2741334Наблюдать
Omron CX-One Versions 4.60 and prior, including CX-Server Versions 5.0.29.0 and prior, are vulnerable to a stack-based buffer overflow, whic
ВысокаяCVSS 7,8Эксплойта нетEPSS 10 %omron · cx-one13 мая 2021 г.
- CVE-2022-2113734Наблюдать
Omron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processing specific project files, which may allo
ВысокаяCVSS 7,8Эксплойта нетEPSS 9 %omron · cx-one14 янв. 2022 г.
- CVE-2022-3320833Наблюдать
Authentication bypass by capture-replay vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machi
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %omron · nx701-1600 firmware3 июл. 2022 г.
- CVE-2022-2641932Наблюдать
Rockwell Automation Studio 5000 Logix Designer Code Injection
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %omron · cx-position1 апр. 2022 г.
- CVE-2020-2725732Наблюдать
This vulnerability allows local attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can re
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %omron · cx-one9 февр. 2021 г.