Show filters
96 Total Results
Displaying 1-10 of 96
Sort by:
Attacker Value
Unknown

CVE-2025-0591

Disclosure Date: February 17, 2025 (last updated February 17, 2025)
Out-of-bounds Read vulnerability (CWE-125) was found in CX-Programmer. Attackers may be able to read sensitive information or cause an application crash by abusing this vulnerability.
0
Attacker Value
Unknown

CVE-2024-12298

Disclosure Date: January 14, 2025 (last updated January 14, 2025)
We found a vulnerability Improper Restriction of XML External Entity Reference (CWE-611) in NB-series NX-Designer. Attackers may be able to abuse this vulnerability to disclose confidential data on a computer.
0
Attacker Value
Unknown

CVE-2024-12083

Disclosure Date: January 14, 2025 (last updated January 14, 2025)
Path Traversal Vulnerabilities (CWE-22) exist in NJ/NX-series Machine Automation Controllers. An attacker may use these vulnerabilities to perform unauthorized access and to execute unauthorized code remotely to the controller products.
0
Attacker Value
Unknown

CVE-2024-49501

Disclosure Date: November 01, 2024 (last updated November 01, 2024)
Sysmac Studio provided by OMRON Corporation contains an incorrect authorization vulnerability. If this vulnerability is exploited, an attacker may access the program which is protected by Data Protection function.
0
Attacker Value
Unknown

CVE-2024-33687

Disclosure Date: June 24, 2024 (last updated June 27, 2024)
Insufficient verification of data authenticity issue exists in NJ Series CPU Unit all versions and NX Series CPU Unit all versions. If a user program in the affected product is altered, the product may not be able to detect the alteration.
Attacker Value
Unknown

CVE-2024-31413

Disclosure Date: May 01, 2024 (last updated May 02, 2024)
Free of pointer not at start of buffer vulnerability exists in CX-One CX-One CXONE-AL[][]D-V4 (The version which was installed with a DVD ver. 4.61.1 or lower, and was updated through CX-One V4 auto update in January 2024 or prior) and Sysmac Studio SYSMAC-SE2[][][] (The version which was installed with a DVD ver. 1.56 or lower, and was updated through Sysmac Studio V1 auto update in January 2024 or prior). Opening a specially crafted project file may lead to arbitrary code execution.
0
Attacker Value
Unknown

CVE-2024-31412

Disclosure Date: May 01, 2024 (last updated May 02, 2024)
Out-of-bounds read vulnerability exists in CX-Programmer included in CX-One CXONE-AL[][]D-V4 Ver. 9.81 or lower. Opening a specially crafted project file may lead to information disclosure and/or the product being crashed.
0
Attacker Value
Unknown

CVE-2024-27121

Disclosure Date: March 12, 2024 (last updated April 01, 2024)
Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary file in the affected product may be accessed or arbitrary code may be executed by processing a specially crafted request sent from a remote attacker with an administrative privilege. As for the details of the affected product names/versions, see the information provided by the vendor under [References] section.
0
Attacker Value
Unknown

CVE-2022-45792

Disclosure Date: January 22, 2024 (last updated January 30, 2024)
Project files may contain malicious contents which the software will use to create files on the filesystem. This allows directory traversal and overwriting files with the privileges of the logged-in user.
Attacker Value
Unknown

CVE-2022-45790

Disclosure Date: January 22, 2024 (last updated January 30, 2024)
The Omron FINS protocol has an authenticated feature to prevent access to memory regions. Authentication is susceptible to bruteforce attack, which may allow an adversary to gain access to protected memory. This access can allow overwrite of values including programmed logic.