← Back

Omron

omron

89 CVEs • 976 products

Products (976)

Click to collapse
Toggle
Cx Programmer
cx-programmer
Cx Supervisor
cx-supervisor
Cx One
cx-one
Cx Server
cx-server
Cx Protocol
cx-protocol
Cx Position
cx-position
Cx Flnet
cx-flnet
Sysmac Studio
sysmac_studio
Cj2h Plc
cj2h_plc
Cj2m Plc
cj2m_plc
Cx Drive
cx-drive

CVEs (89)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Omron
1Cx Programmer
Jun 17, 2026
Mar 10, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Out-of-bounds read vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a...Show more
Out-of-bounds read vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.Show less
1Omron
1Cx Programmer
Jun 17, 2026
Mar 10, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Out-of-bounds write vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a...Show more
Out-of-bounds write vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. This vulnerability is different from CVE-2022-25234.Show less
1Omron
1Cx One
Jun 17, 2026
Jan 14, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Omron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processing specific project files, which may allow an attacker to execute arbitrary code.
1Omron
1Cx Supervisor
Jun 17, 2026
Oct 19, 2021
N/A· v4
6.5 MEDIUM· v3
6.0 MEDIUM· v2
Out-of-bounds read vulnerability in CX-Supervisor v4.0.0.13 and v4.0.0.16 allows an attacker with administrative privileges to cause information disclosure and/or arbitrary code execution by opening a specially crafted S...Show more
Out-of-bounds read vulnerability in CX-Supervisor v4.0.0.13 and v4.0.0.16 allows an attacker with administrative privileges to cause information disclosure and/or arbitrary code execution by opening a specially crafted SCS project files.Show less
1Omron
2Cx One
Cx Server
Jun 17, 2026
May 13, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Omron CX-One Versions 4.60 and prior, including CX-Server Versions 5.0.29.0 and prior, are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.
1Omron
4Cx One
Cx PositionCx Protocol+1 more
Jun 17, 2026
Feb 9, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Omron CX-One Version 4.60 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.
1Omron
4Cx One
Cx PositionCx Protocol+1 more
Jun 17, 2026
Feb 9, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attacker to remotely execute arbitrary code.
1Omron
4Cx One
Cx PositionCx Protocol+1 more
Jun 17, 2026
Feb 9, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
This vulnerability allows local attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can result in a type-confusion condition in the Omron CX-One Version 4.60 and prior de...Show more
This vulnerability allows local attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can result in a type-confusion condition in the Omron CX-One Version 4.60 and prior devices.Show less
1Omron
2Plc Cj1 Firmware
Plc Cj2 Firmware
Jun 17, 2026
Mar 5, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
In all versions of Omron PLC CJ Series, an attacker can send a series of specific data packets within a short period, causing a service error on the PLC Ethernet module, which in turn causes a PLC service denied result.
1Omron
2Plc Cj Firmware
Plc Cs Firmware
Jun 17, 2026
Dec 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Omron’s CS and CJ series PLCs have an unrestricted externally accessible lock vulnerability.
1Omron
3Plc Cj Firmware
Plc Cs FirmwarePlc Nj Firmware
Jun 17, 2026
Dec 16, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In Omron PLC CS series, all versions, Omron PLC CJ series, all versions, and Omron PLC NJ series, all versions, the software does not implement sufficient measures to prevent multiple failed authentication attempts withi...Show more
In Omron PLC CS series, all versions, Omron PLC CJ series, all versions, and Omron PLC NJ series, all versions, the software does not implement sufficient measures to prevent multiple failed authentication attempts within in a short time frame, making it more susceptible to brute force attacks.Show less
1Omron
2Plc Cj Firmware
Plc Cs Firmware
Jun 17, 2026
Dec 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Omron PLC CJ series, all versions and Omron PLC CS series, all versions, an attacker could spoof arbitrary messages or execute commands.
1Omron
2Plc Cj Firmware
Plc Cs Firmware
Jun 17, 2026
Dec 16, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
In Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monitor traffic between the PLC and the controller and replay requests that could result in the opening and closing of indust...Show more
In Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monitor traffic between the PLC and the controller and replay requests that could result in the opening and closing of industrial valves.Show less
2Omron
Teamviewer
2Cx Supervisor
Teamviewer
Jun 17, 2026
Nov 26, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS. This version of Teamviewer is vulnerable to an obsolete function vulnerability requiring user interactio...Show more
In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS. This version of Teamviewer is vulnerable to an obsolete function vulnerability requiring user interaction to exploit.Show less
1Omron
1Network Configurator For Devicenet Safety
Jun 17, 2026
Jun 12, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The application (Network Configurator for DeviceNet Safety 3.41 and prior) searches for resources by means of an untrusted search path that could execute a malicious .dll file not under the application's direct control a...Show more
The application (Network Configurator for DeviceNet Safety 3.41 and prior) searches for resources by means of an untrusted search path that could execute a malicious .dll file not under the application's direct control and outside the intended directories.Show less
1Omron
2Common Components
Cx Programmer
Jun 17, 2026
Apr 10, 2019
N/A· v4
6.6 MEDIUM· v3
6.8 MEDIUM· v2
When processing project files, the application (Omron CX-Programmer v9.70 and prior and Common Components January 2019 and prior) fails to check if it is referencing freed memory. An attacker could use a specially crafte...Show more
When processing project files, the application (Omron CX-Programmer v9.70 and prior and Common Components January 2019 and prior) fails to check if it is referencing freed memory. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.Show less
1Omron
1Poweract Pro Master Agent
Nov 21, 2024
Mar 27, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
PowerAct Pro Master Agent for Windows Version 5.13 and earlier allows authenticated attackers to bypass access restriction to alter or edit unauthorized files via unspecified vectors.
1Omron
1Cx Supervisor
Nov 21, 2024
Feb 12, 2019
N/A· v4
5.0 MEDIUM· v3
3.5 LOW· v2
When CX-Supervisor (Versions 3.42 and prior) processes project files and tampers with the value of an offset, an attacker can force the application to read a value outside of an array.
1Omron
1Cx Supervisor
Nov 21, 2024
Feb 12, 2019
N/A· v4
7.3 HIGH· v3
6.0 MEDIUM· v2
An access of uninitialized pointer vulnerability in CX-Supervisor (Versions 3.42 and prior) could lead to type confusion when processing project files. An attacker could use a specially crafted project file to exploit an...Show more
An access of uninitialized pointer vulnerability in CX-Supervisor (Versions 3.42 and prior) could lead to type confusion when processing project files. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.Show less
1Omron
2Cx One
Cx Protocol
Nov 21, 2024
Jan 30, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Three type confusion vulnerabilities exist in CX-One Versions 4.50 and prior and CX-Protocol Versions 2.0 and prior when processing project files. An attacker could use a specially crafted project file to exploit and exe...Show more
Three type confusion vulnerabilities exist in CX-One Versions 4.50 and prior and CX-Protocol Versions 2.0 and prior when processing project files. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.Show less