QID 591251

Date Published: 2022-12-23

QID 591251: Omron NJ/NX-series Machine Automation Controllers Multiple Vulnerabilities (ICSA-22-314-08, OMSR-2022-001)

AFFECTED PRODUCTS
NX7-series Machine Automation Controller (All Models): Versions 1.28 and prior.
NX1-series Machine Automation Controller (All Models): Versions 1.48 and prior.
NJ-series Machine Automation Controller (All Models): Versions 1.48 and prior.
NA-series Programable Terminal (NA5-15W, NA5-12W, NA5-9W, NA5-7W): Runtime versions 1.15 and prior.

QID Detection Logic:
This QID checks for the Vulnerable version of Omron NJ/NX-series Machine Automation Controllers using passive scanning

Successful exploitation of these vulnerabilities may allow an attacker to bypass authentication in the communications connection process to login and operate the controller products without authorization.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-22-314-08 or Omron MITIGATIONS section OMSR-2022-001 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591251

    Software Advisories
    Advisory ID Software Component Link
    ICSA-22-314-08 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-314-08
    OMSR-2022-001 URL Logo www.ia.omron.com/product/vulnerability/OMSR-2022-001_en.pdf