Omron Vulnerabilities and Affected Products
Vulnerabilities associated with CX-Programmer.
Products
Clear product- CX-Position7 vulnerabilities
- CX-Programmer5 vulnerabilities
- CX-One4 vulnerabilities
- CX-Supervisor4 vulnerabilities
- CX-Protocol3 vulnerabilities
- CX-Server3 vulnerabilities
- CJ-series and CS-series CPU modules2 vulnerabilities
- NS102 vulnerabilities
- NS122 vulnerabilities
- NS152 vulnerabilities
- NS52 vulnerabilities
- NS82 vulnerabilities
- Sysmac Studio2 vulnerabilities
- CJ1M SYSMAC CJ-series1 vulnerability
- CJ1M SYSMAC CP-series1 vulnerability
- CJ1M SYSMAC CS-series1 vulnerability
- cj2h_cpu_unit1 vulnerability
- cj2m_cpu_unit1 vulnerability
- cs_cj_series_ethernet_ip_unit1 vulnerability
- CX-Programmer within CX-One1 vulnerability
- CX-Protocol within CX-One1 vulnerability
- nj101-9020_firmware1 vulnerability
- nj301-1200_firmware1 vulnerability
- nj501-r520_firmware1 vulnerability
- nx701-1600_firmware1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-31412HIGH | Out-of-bounds read vulnerability exists in CX-Programmer included in CX-One CXONE-AL[][]D-V4 Ver. 9.81 or lower. Opening a specially crafted project file may lead to information disclosure and/or the product being crashed. CWE-125May 1, 2024 | CVSS7.8v3.1 | EPSS0.245% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-3396HIGH | OMRON CX-Programmer Out-of-bounds WriteOMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code. CWE-787Oct 6, 2022 | CVSS7.8v3.1 | EPSS0.61% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-3398HIGH | OMRON CX-Programmer Out-of-bounds WriteOMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code. CWE-787Oct 6, 2022 | CVSS7.8v3.1 | EPSS0.61% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-3397HIGH | OMRON CX-Programmer Out-of-bounds WriteOMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code. CWE-787Oct 6, 2022 | CVSS7.8v3.1 | EPSS0.61% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-2979HIGH | Omron CX-ProgrammerOpening a specially crafted file could cause the affected product to fail to release its memory reference potentially resulting in arbitrary code execution. CWE-416Sep 12, 2022 | CVSS7.8v3.1 | EPSS0.236% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |