Known Vulnerabilities for products from Omron

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Omron".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Additional devices specifications by Omron can be found at device.report : Omron

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2023-38748 json Use after free vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user ... 7.8 - HIGH 2023-08-03 2023-08-08
CVE-2023-38747 json Heap-based buffer overflow vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By ha... 7.8 - HIGH 2023-08-03 2023-08-08
CVE-2023-38746 json Out-of-bounds read vulnerability/issue exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By havi... 7.8 - HIGH 2023-08-03 2023-08-08
CVE-2023-38744 json Denial-of-service (DoS) vulnerability due to improper validation of specified type of input issue exists in the built-in Ethe... 7.5 - HIGH 2023-08-03 2023-08-11
CVE-2023-27396 json FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Fact... 9.8 - CRITICAL 2023-06-19 2023-06-30
CVE-2023-27385 json Heap-based buffer overflow vulnerability exists in CX-Drive All models all versions. By having a user open a specially crafte... 7.8 - HIGH 2023-05-10 2023-08-02
CVE-2023-22366 json CX-Motion-MCH v2.32 and earlier contains an access of uninitialized pointer vulnerability. Having a user to open a specially ... 7.8 - HIGH 2023-01-17 2023-01-24
CVE-2023-22357 json Active debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS proto... 9.8 - CRITICAL 2023-01-17 2023-01-24
CVE-2023-22322 json Improper restriction of XML external entity reference (XXE) vulnerability exists in OMRON CX-Motion Pro 1.4.6.013 and earlier... 5.5 - MEDIUM 2023-01-30 2023-02-06
CVE-2023-22317 json Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file... 7.8 - HIGH 2023-08-03 2023-08-08
CVE-2023-22314 json Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file... 7.8 - HIGH 2023-08-03 2023-08-08
CVE-2023-22277 json Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file... 7.8 - HIGH 2023-08-03 2023-08-08
CVE-2023-0811 json Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an adver... 9.1 - CRITICAL 2023-03-16 2023-11-07
CVE-2022-46282 json Use after free vulnerability in CX-Drive V3.00 and earlier allows a local attacker to execute arbitrary code by having a user... 7.8 - HIGH 2022-12-21 2022-12-30
CVE-2022-45794 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 7.5 - HIGH 2024-01-10 2024-01-23
CVE-2022-45793 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 7.8 - HIGH 2024-01-10 2024-01-22
CVE-2022-45792 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 7.8 - HIGH 2024-01-22 2024-01-29
CVE-2022-45790 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 9.1 - CRITICAL 2024-01-22 2024-01-29
CVE-2022-43667 json Stack-based buffer overflow vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosur... 7.8 - HIGH 2022-12-07 2022-12-09
CVE-2022-43509 json Out-of-bounds write vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or... 7.8 - HIGH 2022-12-07 2022-12-09

Known software with vulnerabilities from Omron

Type Vendor Product Version
ApplicationOmronCx-supervisor3.0
ApplicationOmronNetwork Configurator For Devicenet Safety3.41
HardwareOmronNs10 Hmi Terminal-
HardwareOmronNs12 Hmi Terminal-
HardwareOmronNs15 Hmi Terminal-
HardwareOmronNs5 Hmi Terminal-
HardwareOmronNs8 Hmi Terminal-
Operating
System
OmronNs Series System Program Firmware8.1
HardwareOmronPlc Cj1-
Operating
System
OmronPlc Cj1 Firmware-
HardwareOmronPlc Cj2-
Operating
System
OmronPlc Cj2 Firmware-
Operating
System
OmronPlc Nj Firmware-
ApplicationOmronPoweract Pro Master Agent4.1
ApplicationOmronTeamviewer5.0.8703_qs