CVE-2019-18269
Summary
| CVE | CVE-2019-18269 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-12-16 20:15:15 UTC |
| Updated | 2026-06-02 21:16:23 UTC |
| Description | Omron’s CS and CJ series PLCs have an unrestricted externally accessible lock vulnerability. |
Risk And Classification
Primary CVSS: v3.1 9.8 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.001960000 probability, percentile 0.414270000 (date 2026-06-04)
Problem Types: CWE-412 | NVD-CWE-Other | CWE-412 CWE-412 Unrestricted Externally Accessible Lock
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | ADP | DECLARED | 8.6 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 8.6 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H |
| 2.0 | [email protected] | Primary | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
AV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Omron | Plc Cj Firmware | All | All | All | All |
| Operating System | Omron | Plc Cs Firmware | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Omron | Omron PLC CJ Series | affected all versions | Not specified |
| CNA | Omron | Omron PLC CS Series | affected all versions | Not specified |
| CNA | Omron | Omron PLC NX1P2 Series | affected all versions | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.omron-cxone.com/security/2019-12-06_PLC_EN.pdf | af854a3a-2127-422b-91ae-364da2661108 | www.omron-cxone.com | |
| Omron PLC CJ and CS Series (Update B) | CISA | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Jipeng You (XDU) and n0b0dy reported these vulnerabilities to CISA. (en)
Additional Advisory Data
Workarounds
CNA: Omron recommends the following mitigation measures: * Filter FINS port: Protect access to Omron’s PLC with a firewall and blocking unnecessary remote access to FINS port (default: 9600). * Filter IP addresses: Protect access to Omron’s PLC with a firewall and filtering devices connected to the PLC by IP address. For more information provided by Omron on these vulnerabilities refer to Vulnerabilities in Omron CS and CJ series CPU PLCs https://gcc01.safelinks.protection.outlook.com/ .
Legacy QID Mappings
- 590463 Omron PLC CJ and CS Series Multiple Vulnerabilities (ICSA-19-346-02)