QID 591183

Date Published: 2022-11-18

QID 591183: Omron NJ/NX-series Machine Automation Controllers Vulnerability (ICSA-22-314-07)

AFFECTED PRODUCTS
The following products of the NJ/NX-series Machine Automation Controllers are affected:
NX7-series Machine Automation Controller (All Models): Versions 1.28 and prior
NX1-series Machine Automation Controller (All Models): Versions 1.48 and prior
NJ-series Machine Automation Controller (All Models): Versions 1.48 and prior

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of this vulnerability could allow an attacker to obtain unauthorized access to the device and cause the device to be in an "out of service" state or execute a malicious program on the device.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section icsa-22-314-07 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591183

    Software Advisories
    Advisory ID Software Component Link
    icsa-22-314-07 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-314-07