Omron
omron
89 CVEs • 976 products
Products (976)
Click to collapseToggle
Products (976)
Click to collapse
CVEs (89)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Omron 55Nj Pa3001 Firmware Nj Pd3001 FirmwareNj101 1000 Firmware+52 moreJun 17, 2026 Jun 24, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Insufficient verification of data authenticity issue exists in NJ Series CPU Unit all versions and NX Series CPU Unit all versions. If a user program in the affected product is altered, the product may not be able to det...Show more |
Project files may contain malicious contents which the software will use to create files on the filesystem. This allows directory traversal and overwriting files with the privileges of the logged-in user. |
1Omron 46Cj1g Cpu42p Firmware Cj1g Cpu43p FirmwareCj1g Cpu44p Firmware+43 moreJun 17, 2026 Jan 22, 2024 N/A· v4 9.1 CRITICAL· v3 N/A· v2 The Omron FINS protocol has an authenticated feature to prevent access to memory regions. Authentication is susceptible to bruteforce attack, which may allow an adversary to gain access to protected memory. This access c...Show more |
1Omron 41Sysmac Cj1g Cpu42p Firmware Sysmac Cj1g Cpu43p FirmwareSysmac Cj1g Cpu44p Firmware+38 moreJun 17, 2026 Jan 10, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 An attacker with network access to the affected PLC (CJ-series and CS-series PLCs, all versions) may use a network protocol to read and write files on the PLC internal memory and memory card.
|
1Omron 1Automation Software Sysmac Studio Jun 17, 2026 Jan 10, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Sysmac Studio installs executables in a directory with poor permissions. This can allow a locally-authenticated attacker to overwrite files which will result in code execution with privileges of a different user. |
Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is diffe...Show more |
Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is diffe...Show more |
Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is diffe...Show more |
Use after free vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may o...Show more |
Heap-based buffer overflow vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code exe...Show more |
Out-of-bounds read vulnerability/issue exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execu...Show more |
1Omron 12Cj1w Eip21 Firmware Cj2h Cpu64 Eip FirmwareCj2h Cpu65 Eip Firmware+9 moreJun 17, 2026 Aug 3, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Denial-of-service (DoS) vulnerability due to improper validation of specified type of input issue exists in the built-in EtherNet/IP port of the CJ Series CJ2 CPU unit and the communication function of the CS/CJ Series E...Show more |
1Omron 271Cj2h Cpu64 Eip Firmware Cj2h Cpu64 FirmwareCj2h Cpu65 Eip Firmware+268 moreJun 17, 2026 Jun 19, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation) networks, and is used in FA networks composed of OMRON products. Multiple OMRON...Show more |
Heap-based buffer overflow vulnerability exists in CX-Drive All models all versions. By having a user open a specially crafted SDD file, arbitrary code may be executed and/or information may be disclosed.
|
1Omron 128Sysmac Cj2h Cpu64 Eip Firmware Sysmac Cj2h Cpu64 FirmwareSysmac Cj2h Cpu65 Eip Firmware+125 moreJun 17, 2026 Mar 16, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an adversary issues a PROGRAM AREA WRITE command to a specific memory region, they could overwrite the...Show more |
Improper restriction of XML external entity reference (XXE) vulnerability exists in OMRON CX-Motion Pro 1.4.6.013 and earlier. If a user opens a specially crafted project file created by an attacker, sensitive informatio...Show more |
CX-Motion-MCH v2.32 and earlier contains an access of uninitialized pointer vulnerability. Having a user to open a specially crafted project file may lead to information disclosure and/or arbitrary code execution. |
Active debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS protocol being executed without authentication. A remote unauthenticated attacker may read/write in...Show more |
Use after free vulnerability in CX-Drive V3.00 and earlier allows a local attacker to execute arbitrary code by having a user to open a specially crafted file, |
Stack-based buffer overflow vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. |