Omron kayıtları
omron üreticisine ait 91 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 9
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-416 Use After Free15
- CWE-787 Out-of-bounds Write11
- CWE-121 Stack-based Buffer Overflow7
- CWE-125 Out-of-bounds Read5
- CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
91 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
44Planlayın | CVE-2000-0704Kavram kanıtı | Buffer overflow in SGI Omron WorldView Wnn allows remote attackers to execute arbitrary commands via long JS_OPEN, JS_MKDIR, or JS_FILE_INFOomron · worldview | Kritik10,0 | — | %13,1 | 20 Eki 2000 |
40Planlayın | CVE-2019-18259İstismar yok | In Omron PLC CJ series, all versions and Omron PLC CS series, all versions, an attacker could spoof arbitrary messages or execute commands.omron · plc cj firmware · CWE-290 | Kritik9,8 | — | %2,1 | 16 Ara 2019 |
40Planlayın | CVE-2015-0987İstismar yok | Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission,omron · cx-programmer · CWE-200 | Kritik10,0 | — | %1,2 | 5 Eki 2015 |
39İzleyin | CVE-2018-6624İstismar yok | OMRON NS devices 1.1 through 1.3 allow remote attackers to bypass authentication via a direct request to the .html file for a specific screeomron · ns series firmware · CWE-425 | Kritik9,8 | — | %1,6 | 5 Şub 2018 |
39İzleyin | CVE-2023-27396İstismar yok | FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation)omron · cs1w-eip21 firmware · CWE-306 | Kritik9,8 | — | %1,4 | 19 Haz 2023 |
39İzleyin | CVE-2019-18261İstismar yok | In Omron PLC CS series, all versions, Omron PLC CJ series, all versions, and Omron PLC NJ series, all versions, the software does not implemomron · plc cj firmware · CWE-307 | Kritik9,8 | — | %1,3 | 16 Ara 2019 |
39İzleyin | CVE-2023-22357İstismar yok | Active debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS protocol being execuomron · cp1l-el20dr-d firmware · CWE-489 | Kritik9,8 | — | %1,2 | 17 Oca 2023 |
39İzleyin | CVE-2022-31206İstismar yok | The Omron SYSMAC Nx product family PLCs (NJ series, NY series, NX series, and PMAC series) through 2022-005-18 lack cryptographic authenticaomron · nx701-1600 firmware · CWE-347 | Kritik9,8 | — | %1,1 | 26 Tem 2022 |
39İzleyin | CVE-2019-18269İstismar yok | Omron’s CS and CJ series PLCs have an unrestricted externally accessible lock vulnerability.omron · plc cj firmware · CWE-412 | Kritik9,8 | — | %1,0 | 16 Ara 2019 |
39İzleyin | CVE-2022-31207İstismar yok | The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic authentication.omron · sysmac cs1 firmware · CWE-347 | Kritik9,8 | — | %1,0 | 26 Tem 2022 |
39İzleyin | CVE-2022-3396İstismar yok | OMRON CX-Programmer Out-of-bounds Writeomron · cx-programmer · CWE-787 | Kritik9,8 | — | %0,6 | 6 Eki 2022 |
39İzleyin | CVE-2022-3398İstismar yok | OMRON CX-Programmer Out-of-bounds Writeomron · cx-programmer · CWE-787 | Kritik9,8 | — | %0,6 | 6 Eki 2022 |
39İzleyin | CVE-2022-3397İstismar yok | OMRON CX-Programmer Out-of-bounds Writeomron · cx-programmer · CWE-787 | Kritik9,8 | — | %0,6 | 6 Eki 2022 |
37İzleyin | CVE-2020-27261İstismar yok | The Omron CX-One Version 4.60 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbiomron · cx-one · CWE-121 | Yüksek8,8 | — | %7,6 | 9 Şub 2021 |
36İzleyin | CVE-2020-27259İstismar yok | The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attackeromron · cx-one · CWE-822 | Yüksek8,8 | — | %2,7 | 9 Şub 2021 |
36İzleyin | CVE-2018-19011İstismar yok | CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file.omron · cx-supervisor · CWE-94 | Yüksek8,8 | — | %2,4 | 22 Oca 2019 |
36İzleyin | CVE-2018-19017İstismar yok | Several use after free vulnerabilities have been identified in CX-Supervisor (Versions 3.42 and prior).omron · cx-supervisor · CWE-416 | Yüksek8,8 | — | %2,4 | 22 Oca 2019 |
36İzleyin | CVE-2019-18251İstismar yok | In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS.omron · cx-supervisor · CWE-477 | Yüksek8,8 | — | %1,7 | 25 Kas 2019 |
36İzleyin | CVE-2022-45790İstismar yok | Omron FINS memory protection susceptible to bruteforceomron · cj1g-cpu45p firmware · CWE-307 | Kritik9,1 | — | %0,9 | 22 Oca 2024 |
36İzleyin | CVE-2023-0811İstismar yok | Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored.omron · sysmac cj2h-cpu64 firmware · CWE-284 | Kritik9,1 | — | %0,6 | 16 Mar 2023 |
34İzleyin | CVE-2021-27413İstismar yok | Omron CX-One Versions 4.60 and prior, including CX-Server Versions 5.0.29.0 and prior, are vulnerable to a stack-based buffer overflow, whicomron · cx-one · CWE-121 | Yüksek7,8 | — | %10,0 | 13 May 2021 |
34İzleyin | CVE-2022-21137İstismar yok | Omron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processing specific project files, which may alloomron · cx-one · CWE-121 | Yüksek7,8 | — | %9,3 | 14 Oca 2022 |
33İzleyin | CVE-2022-33208İstismar yok | Authentication bypass by capture-replay vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machiomron · nx701-1600 firmware · CWE-294 | Yüksek8,1 | — | %1,9 | 3 Tem 2022 |
32İzleyin | CVE-2022-26419İstismar yok | Rockwell Automation Studio 5000 Logix Designer Code Injectionomron · cx-position · CWE-121 | Yüksek7,8 | — | %2,1 | 1 Nis 2022 |
32İzleyin | CVE-2020-27257İstismar yok | This vulnerability allows local attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can reomron · cx-one · CWE-843 | Yüksek7,8 | — | %1,8 | 9 Şub 2021 |
- CVE-2000-070444Planlayın
Buffer overflow in SGI Omron WorldView Wnn allows remote attackers to execute arbitrary commands via long JS_OPEN, JS_MKDIR, or JS_FILE_INFO
KritikCVSS 10,0Kavram kanıtıEPSS %13omron · worldview20 Eki 2000
- CVE-2019-1825940Planlayın
In Omron PLC CJ series, all versions and Omron PLC CS series, all versions, an attacker could spoof arbitrary messages or execute commands.
KritikCVSS 9,8İstismar yokEPSS %2omron · plc cj firmware16 Ara 2019
- CVE-2015-098740Planlayın
Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission,
KritikCVSS 10,0İstismar yokEPSS %1omron · cx-programmer5 Eki 2015
- CVE-2018-662439İzleyin
OMRON NS devices 1.1 through 1.3 allow remote attackers to bypass authentication via a direct request to the .html file for a specific scree
KritikCVSS 9,8İstismar yokEPSS %2omron · ns series firmware5 Şub 2018
- CVE-2023-2739639İzleyin
FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation)
KritikCVSS 9,8İstismar yokEPSS %1omron · cs1w-eip21 firmware19 Haz 2023
- CVE-2019-1826139İzleyin
In Omron PLC CS series, all versions, Omron PLC CJ series, all versions, and Omron PLC NJ series, all versions, the software does not implem
KritikCVSS 9,8İstismar yokEPSS %1omron · plc cj firmware16 Ara 2019
- CVE-2023-2235739İzleyin
Active debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS protocol being execu
KritikCVSS 9,8İstismar yokEPSS %1omron · cp1l-el20dr-d firmware17 Oca 2023
- CVE-2022-3120639İzleyin
The Omron SYSMAC Nx product family PLCs (NJ series, NY series, NX series, and PMAC series) through 2022-005-18 lack cryptographic authentica
KritikCVSS 9,8İstismar yokEPSS %1omron · nx701-1600 firmware26 Tem 2022
- CVE-2019-1826939İzleyin
Omron’s CS and CJ series PLCs have an unrestricted externally accessible lock vulnerability.
KritikCVSS 9,8İstismar yokEPSS %1omron · plc cj firmware16 Ara 2019
- CVE-2022-3120739İzleyin
The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic authentication.
KritikCVSS 9,8İstismar yokEPSS %1omron · sysmac cs1 firmware26 Tem 2022
- CVE-2022-339639İzleyin
OMRON CX-Programmer Out-of-bounds Write
KritikCVSS 9,8İstismar yokEPSS %1omron · cx-programmer6 Eki 2022
- CVE-2022-339839İzleyin
OMRON CX-Programmer Out-of-bounds Write
KritikCVSS 9,8İstismar yokEPSS %1omron · cx-programmer6 Eki 2022
- CVE-2022-339739İzleyin
OMRON CX-Programmer Out-of-bounds Write
KritikCVSS 9,8İstismar yokEPSS %1omron · cx-programmer6 Eki 2022
- CVE-2020-2726137İzleyin
The Omron CX-One Version 4.60 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbi
YüksekCVSS 8,8İstismar yokEPSS %8omron · cx-one9 Şub 2021
- CVE-2020-2725936İzleyin
The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attacker
YüksekCVSS 8,8İstismar yokEPSS %3omron · cx-one9 Şub 2021
- CVE-2018-1901136İzleyin
CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file.
YüksekCVSS 8,8İstismar yokEPSS %2omron · cx-supervisor22 Oca 2019
- CVE-2018-1901736İzleyin
Several use after free vulnerabilities have been identified in CX-Supervisor (Versions 3.42 and prior).
YüksekCVSS 8,8İstismar yokEPSS %2omron · cx-supervisor22 Oca 2019
- CVE-2019-1825136İzleyin
In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS.
YüksekCVSS 8,8İstismar yokEPSS %2omron · cx-supervisor25 Kas 2019
- CVE-2022-4579036İzleyin
Omron FINS memory protection susceptible to bruteforce
KritikCVSS 9,1İstismar yokEPSS %1omron · cj1g-cpu45p firmware22 Oca 2024
- CVE-2023-081136İzleyin
Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored.
KritikCVSS 9,1İstismar yokEPSS %1omron · sysmac cj2h-cpu64 firmware16 Mar 2023
- CVE-2021-2741334İzleyin
Omron CX-One Versions 4.60 and prior, including CX-Server Versions 5.0.29.0 and prior, are vulnerable to a stack-based buffer overflow, whic
YüksekCVSS 7,8İstismar yokEPSS %10omron · cx-one13 May 2021
- CVE-2022-2113734İzleyin
Omron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processing specific project files, which may allo
YüksekCVSS 7,8İstismar yokEPSS %9omron · cx-one14 Oca 2022
- CVE-2022-3320833İzleyin
Authentication bypass by capture-replay vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machi
YüksekCVSS 8,1İstismar yokEPSS %2omron · nx701-1600 firmware3 Tem 2022
- CVE-2022-2641932İzleyin
Rockwell Automation Studio 5000 Logix Designer Code Injection
YüksekCVSS 7,8İstismar yokEPSS %2omron · cx-position1 Nis 2022
- CVE-2020-2725732İzleyin
This vulnerability allows local attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can re
YüksekCVSS 7,8İstismar yokEPSS %2omron · cx-one9 Şub 2021