CVE-2024-12083
MEDIUMOMRON Machine Automation Controller NJ-series < 1.64.05 - Path Traversal and Remote Code Execution
Title source: llmDescription
Path Traversal Vulnerabilities (CWE-22) exist in NJ/NX-series Machine Automation Controllers. An attacker may use these vulnerabilities to perform unauthorized access and to execute unauthorized code remotely to the controller products.
References (2)
Core 2
Core References
Scores
CVSS v3
6.6
EPSS
0.0064
EPSS Percentile
45.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-22
Status
published
Products (15)
OMRON Corporation/Machine Automation Controller NJ-series
NJ101-[][][][] Ver.1.64.05 and lower
OMRON Corporation/Machine Automation Controller NJ-series
NJ301-[][][][] Ver.1.64.05 and lower
OMRON Corporation/Machine Automation Controller NJ-series
NJ501-1340 Ver.1.64.04 and lower
OMRON Corporation/Machine Automation Controller NJ-series
NJ501-1[]0[] Ver.1.64.05 and lower
OMRON Corporation/Machine Automation Controller NJ-series
NJ501-1[]2[] Ver.1.64.04 and lower
OMRON Corporation/Machine Automation Controller NJ-series
NJ501-4[][][] Ver.1.64.04 and lower
OMRON Corporation/Machine Automation Controller NJ-series
NJ501-5300 Ver.1.64.04 and lower
OMRON Corporation/Machine Automation Controller NJ-series
NJ501-R[][][] Ver.1.64.04 and lower
OMRON Corporation/Machine Automation Controller NX-series
NX-EIP201 Ver.1.01.02 and lower
OMRON Corporation/Machine Automation Controller NX-series
NX102-[][]0[] Ver.1.64.07 and lower
... and 5 more
Published
Jan 14, 2025
Tracked Since
Feb 18, 2026