Vulnerabilities > Omron > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-03-10 | CVE-2022-21219 | Out-of-bounds Read vulnerability in Omron Cx-Programmer Out-of-bounds read vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. | 6.8 |
2022-01-14 | CVE-2022-21137 | Out-of-bounds Write vulnerability in Omron Cx-One 4.42/4.50/4.60 Omron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processing specific project files, which may allow an attacker to execute arbitrary code. | 6.8 |
2021-10-19 | CVE-2021-20836 | Out-of-bounds Read vulnerability in Omron Cx-Supervisor 4.0.0.13/4.0.0.16 Out-of-bounds read vulnerability in CX-Supervisor v4.0.0.13 and v4.0.0.16 allows an attacker with administrative privileges to cause information disclosure and/or arbitrary code execution by opening a specially crafted SCS project files. | 6.0 |
2021-05-13 | CVE-2021-27413 | Out-of-bounds Write vulnerability in Omron Cx-One and Cx-Server Omron CX-One Versions 4.60 and prior, including CX-Server Versions 5.0.29.0 and prior, are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code. | 6.8 |
2021-02-09 | CVE-2020-27261 | Out-of-bounds Write vulnerability in Omron products The Omron CX-One Version 4.60 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code. | 6.8 |
2021-02-09 | CVE-2020-27259 | Unspecified vulnerability in Omron products The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attacker to remotely execute arbitrary code. network omron | 6.8 |
2021-02-09 | CVE-2020-27257 | Type Confusion vulnerability in Omron products This vulnerability allows local attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can result in a type-confusion condition in the Omron CX-One Version 4.60 and prior devices. | 6.8 |
2019-12-16 | CVE-2019-18261 | Improper Restriction of Excessive Authentication Attempts vulnerability in Omron PLC CJ Firmware, PLC CS Firmware and PLC NJ Firmware In Omron PLC CS series, all versions, Omron PLC CJ series, all versions, and Omron PLC NJ series, all versions, the software does not implement sufficient measures to prevent multiple failed authentication attempts within in a short time frame, making it more susceptible to brute force attacks. | 5.0 |
2019-12-16 | CVE-2019-13533 | Authentication Bypass by Capture-replay vulnerability in Omron PLC CJ Firmware and PLC CS Firmware In Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monitor traffic between the PLC and the controller and replay requests that could result in the opening and closing of industrial valves. | 6.8 |
2019-11-26 | CVE-2019-18251 | In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS. | 6.8 |