CVE-2024-12083

MEDIUM

OMRON Machine Automation Controller NJ-series < 1.64.05 - Path Traversal and Remote Code Execution

Title source: llm
STIX 2.1

Description

Path Traversal Vulnerabilities (CWE-22) exist in NJ/NX-series Machine Automation Controllers. An attacker may use these vulnerabilities to perform unauthorized access and to execute unauthorized code remotely to the controller products.

Scores

CVSS v3 6.6
EPSS 0.0064
EPSS Percentile 45.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (15)
OMRON Corporation/Machine Automation Controller NJ-series NJ101-[][][][] Ver.1.64.05 and lower
OMRON Corporation/Machine Automation Controller NJ-series NJ301-[][][][] Ver.1.64.05 and lower
OMRON Corporation/Machine Automation Controller NJ-series NJ501-1340 Ver.1.64.04 and lower
OMRON Corporation/Machine Automation Controller NJ-series NJ501-1[]0[] Ver.1.64.05 and lower
OMRON Corporation/Machine Automation Controller NJ-series NJ501-1[]2[] Ver.1.64.04 and lower
OMRON Corporation/Machine Automation Controller NJ-series NJ501-4[][][] Ver.1.64.04 and lower
OMRON Corporation/Machine Automation Controller NJ-series NJ501-5300 Ver.1.64.04 and lower
OMRON Corporation/Machine Automation Controller NJ-series NJ501-R[][][] Ver.1.64.04 and lower
OMRON Corporation/Machine Automation Controller NX-series NX-EIP201 Ver.1.01.02 and lower
OMRON Corporation/Machine Automation Controller NX-series NX102-[][]0[] Ver.1.64.07 and lower
... and 5 more
Published Jan 14, 2025
Tracked Since Feb 18, 2026