Search

Find a vulnerability

Search criteria

    150 vulnerabilities by omron

    CVE-2024-31412 (GCVE-0-2024-31412)

    Vulnerability from nvd – Published: 2024-05-01 12:52 – Updated: 2024-08-02 01:52
    VLAI
    Summary
    Out-of-bounds read vulnerability exists in CX-Programmer included in CX-One CXONE-AL[][]D-V4 Ver. 9.81 or lower. Opening a specially crafted project file may lead to information disclosure and/or the product being crashed.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-25 14:29 UTC
    CWE
    • Out-of-bounds read
    • CWE-125 - Out-of-bounds Read
    Impacted products
    Vendor Product Version
    OMRON Corporation CX-Programmer Affected: Included in CX-One CXONE-AL[][]D-V4 Ver. 9.81 or lower
    Create a notification for this product.
    omron cx-programmer Affected: 0 , ≤ 9.81 (custom)
        cpe:2.3:a:omron:cx-programmer:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:omron:cx-programmer:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "cx-programmer",
                "vendor": "omron",
                "versions": [
                  {
                    "lessThanOrEqual": "9.81",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-31412",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-25T14:29:07.641532Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-125",
                    "description": "CWE-125 Out-of-bounds Read",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-25T14:36:05.441Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T01:52:56.842Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2024-003_en.pdf"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU98274902/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CX-Programmer",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Included in CX-One CXONE-AL[][]D-V4 Ver. 9.81 or lower"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Out-of-bounds read vulnerability exists in CX-Programmer included in CX-One CXONE-AL[][]D-V4 Ver. 9.81 or lower. Opening a specially crafted project file may lead to information disclosure and/or the product being crashed."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Out-of-bounds read",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-05-01T12:52:13.173Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2024-003_en.pdf"
            },
            {
              "url": "https://jvn.jp/en/vu/JVNVU98274902/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2024-31412",
        "datePublished": "2024-05-01T12:52:13.173Z",
        "dateReserved": "2024-04-03T10:57:10.684Z",
        "dateUpdated": "2024-08-02T01:52:56.842Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-27121 (GCVE-0-2024-27121)

    Vulnerability from nvd – Published: 2024-03-12 07:55 – Updated: 2024-08-16 19:50
    VLAI
    Summary
    Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary file in the affected product may be accessed or arbitrary code may be executed by processing a specially crafted request sent from a remote attacker with an administrative privilege. As for the details of the affected product names/versions, see the information provided by the vendor under [References] section.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-12 18:25 UTC
    CWE
    • Path traversal
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    OMRON Corporation Machine Automation Controller NJ Series Affected: NJ101-[][][][] Ver.1.64.03 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NJ Series Affected: NJ301-[][][][] Ver.1.64.00 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NJ Series Affected: NJ501-1[]0[] Ver.1.64.03 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NJ Series Affected: NJ501-1[]2[] Ver.1.64.00 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NJ Series Affected: NJ501-1340 Ver.1.64.00 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NJ Series Affected: NJ501-4[][][] Ver.1.64.00 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NJ Series Affected: NJ501-5300 Ver.1.64.00 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NJ Series Affected: NJ501-R[][][] Ver.1.64.00 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NX Series Affected: NX1P2-[][][][][][] Ver.1.64.00 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NX Series Affected: NX1P2-[][][][][][]1 Ver.1.64.00 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NX Series Affected: NX102-[][][][] Ver.1.64.00 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NX Series Affected: NX502-[][][][] Ver.1.65.01 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NX Series Affected: NX701-[][][][] Ver.1.35.00 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NX Series Affected: NX-EIP201 Ver.1.00.01 and earlier
    Create a notification for this product.
    omron nj101-9020_firmware Affected: 0 , ≤ 1.64.03 (custom)
        cpe:2.3:o:omron:nj101-1000_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj101-1020_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj101-9000_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj101-9020_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    omron nj301-1200_firmware Affected: 0 , ≤ 1.64.00 (custom)
        cpe:2.3:o:omron:nj301-1100_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj301-1200_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    omron nj501-r520_firmware Affected: 0 , ≤ 1.64.00 (custom)
        cpe:2.3:o:omron:nj501-1300_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-1320_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-1340_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-1400_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-1420_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-1500_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-1520_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-4300_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-4310_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-4320_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-4400_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-4500_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-5300_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-r300_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-r320_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-r400_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-r420_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-r500_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-r520_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T00:27:59.260Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2024-001_en.pdf"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.fa.omron.co.jp/product/security/assets/pdf/ja/OMSR-2024-001_ja.pdf"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU95852116/index.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:omron:nj101-1000_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj101-1020_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj101-9000_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj101-9020_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "nj101-9020_firmware",
                "vendor": "omron",
                "versions": [
                  {
                    "lessThanOrEqual": "1.64.03",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:omron:nj301-1100_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj301-1200_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "nj301-1200_firmware",
                "vendor": "omron",
                "versions": [
                  {
                    "lessThanOrEqual": "1.64.00",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:omron:nj501-1300_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-1320_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-1340_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-1400_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-1420_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-1500_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-1520_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-4300_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-4310_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-4320_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-4400_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-4500_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-5300_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-r300_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-r320_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-r400_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-r420_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-r500_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-r520_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "nj501-r520_firmware",
                "vendor": "omron",
                "versions": [
                  {
                    "lessThanOrEqual": "1.64.00",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.2,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "HIGH",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-27121",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-12T18:25:40.523309Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-22",
                    "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-16T19:50:12.016Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Machine Automation Controller NJ Series ",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NJ101-[][][][] Ver.1.64.03 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NJ Series ",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NJ301-[][][][] Ver.1.64.00 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NJ Series ",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NJ501-1[]0[] Ver.1.64.03 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NJ Series ",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NJ501-1[]2[] Ver.1.64.00 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NJ Series ",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NJ501-1340 Ver.1.64.00 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NJ Series ",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NJ501-4[][][] Ver.1.64.00 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NJ Series ",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NJ501-5300 Ver.1.64.00 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NJ Series ",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NJ501-R[][][] Ver.1.64.00 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NX Series",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NX1P2-[][][][][][] Ver.1.64.00 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NX Series",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NX1P2-[][][][][][]1 Ver.1.64.00 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NX Series",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NX102-[][][][] Ver.1.64.00 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NX Series",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NX502-[][][][] Ver.1.65.01 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NX Series",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NX701-[][][][] Ver.1.35.00 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NX Series",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NX-EIP201 Ver.1.00.01 and earlier "
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary file in the affected product may be accessed or arbitrary code may be executed by processing a specially crafted request sent from a remote attacker with an administrative privilege. As for the details of the affected product names/versions, see the information provided by the vendor under [References] section."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Path traversal",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-12T07:55:48.301Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2024-001_en.pdf"
            },
            {
              "url": "https://www.fa.omron.co.jp/product/security/assets/pdf/ja/OMSR-2024-001_ja.pdf"
            },
            {
              "url": "https://jvn.jp/en/vu/JVNVU95852116/index.html"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2024-27121",
        "datePublished": "2024-03-12T07:55:48.301Z",
        "dateReserved": "2024-02-20T08:22:05.133Z",
        "dateUpdated": "2024-08-16T19:50:12.016Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-45792 (GCVE-0-2022-45792)

    Vulnerability from nvd – Published: 2024-01-22 17:46 – Updated: 2025-06-17 21:19
    VLAI
    Title
    Directory Traversal in Project File Format allows overwrite (Zip Slip)
    Summary
    Project files may contain malicious contents which the software will use to create files on the filesystem. This allows directory traversal and overwriting files with the privileges of the logged-in user.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-01-30 18:36 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    Omron Sysmac Studio Affected: 0 , < 1.54.0 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T14:17:04.101Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.dragos.com/advisory/omron-plc-and-engineering-software-network-and-file-format-access/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-45792",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-01-30T18:36:27.204028Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-06-17T21:19:25.577Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows",
                "x86",
                "64 bit"
              ],
              "product": "Sysmac Studio",
              "vendor": "Omron",
              "versions": [
                {
                  "lessThan": "1.54.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Project files may contain malicious contents which the software will use to create files on the filesystem. This allows directory traversal and overwriting files with the privileges of the logged-in user."
                }
              ],
              "value": "Project files may contain malicious contents which the software will use to create files on the filesystem. This allows directory traversal and overwriting files with the privileges of the logged-in user."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-165",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-165 File Manipulation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-22T17:46:36.699Z",
            "orgId": "12bdf821-1545-4a87-aac5-61670cc6fcef",
            "shortName": "Dragos"
          },
          "references": [
            {
              "url": "https://www.dragos.com/advisory/omron-plc-and-engineering-software-network-and-file-format-access/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Directory Traversal in Project File Format allows overwrite (Zip Slip)",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "12bdf821-1545-4a87-aac5-61670cc6fcef",
        "assignerShortName": "Dragos",
        "cveId": "CVE-2022-45792",
        "datePublished": "2024-01-22T17:46:36.699Z",
        "dateReserved": "2022-11-22T17:52:43.198Z",
        "dateUpdated": "2025-06-17T21:19:25.577Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-45793 (GCVE-0-2022-45793)

    Vulnerability from nvd – Published: 2024-01-10 20:49 – Updated: 2025-04-17 15:42
    VLAI
    Title
    Executable files writable by low-privileged users in Omron Sysmac Studio
    Summary
    Sysmac Studio installs executables in a directory with poor permissions. This can allow a locally-authenticated attacker to overwrite files which will result in code execution with privileges of a different user.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-01-11 19:43 UTC
    CWE
    • CWE-276 - Incorrect Default Permissions
    Impacted products
    Vendor Product Version
    Omron Sysmac Studio Affected: 0 , ≤ 1.54.0 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T14:17:04.086Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-262-04"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.dragos.com/advisory/omron-plc-and-engineering-software-network-and-file-format-access/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2023-009_en.pdf"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-45793",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-01-11T19:43:03.624295Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-17T15:42:42.580Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "platforms": [
                "Windows",
                "64 bit",
                "32 bit"
              ],
              "product": "Sysmac Studio",
              "vendor": "Omron",
              "versions": [
                {
                  "lessThanOrEqual": "1.54.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Reid Wightman of Dragos"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Sysmac Studio installs executables in a directory with poor permissions. This can allow a locally-authenticated attacker to overwrite files which will result in code execution with privileges of a different user."
                }
              ],
              "value": "Sysmac Studio installs executables in a directory with poor permissions. This can allow a locally-authenticated attacker to overwrite files which will result in code execution with privileges of a different user."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-558",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-558 Replace Trusted Executable"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-276",
                  "description": "CWE-276 Incorrect Default Permissions",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-22T16:32:24.144Z",
            "orgId": "12bdf821-1545-4a87-aac5-61670cc6fcef",
            "shortName": "Dragos"
          },
          "references": [
            {
              "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-262-04"
            },
            {
              "url": "https://www.dragos.com/advisory/omron-plc-and-engineering-software-network-and-file-format-access/"
            },
            {
              "url": "https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2023-009_en.pdf"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Executable files writable by low-privileged users in Omron Sysmac Studio",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "12bdf821-1545-4a87-aac5-61670cc6fcef",
        "assignerShortName": "Dragos",
        "cveId": "CVE-2022-45793",
        "datePublished": "2024-01-10T20:49:36.082Z",
        "dateReserved": "2022-11-22T17:52:43.199Z",
        "dateUpdated": "2025-04-17T15:42:42.580Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-22277 (GCVE-0-2023-22277)

    Vulnerability from nvd – Published: 2023-08-03 13:05 – Updated: 2024-10-17 14:21
    VLAI
    Summary
    Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22317 and CVE-2023-22314.
    Severity
    No CVSS data available.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-17 14:21 UTC
    CWE
    • Use after free
    References
    Impacted products
    Vendor Product Version
    OMRON Corporation CX-Programmer Affected: Ver.9.79 and earlier
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T10:07:05.433Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU92877622/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-22277",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-17T14:21:26.727465Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-17T14:21:36.037Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CX-Programmer",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.9.79 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22317 and CVE-2023-22314."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Use after free",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-03T13:05:45.204Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://jvn.jp/en/vu/JVNVU92877622/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2023-22277",
        "datePublished": "2023-08-03T13:05:45.204Z",
        "dateReserved": "2022-12-27T15:57:55.077Z",
        "dateUpdated": "2024-10-17T14:21:36.037Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-22317 (GCVE-0-2023-22317)

    Vulnerability from nvd – Published: 2023-08-03 12:56 – Updated: 2024-10-17 15:34
    VLAI
    Summary
    Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22277 and CVE-2023-22314.
    Severity
    No CVSS data available.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-17 15:33 UTC
    CWE
    • Use after free
    References
    Impacted products
    Vendor Product Version
    OMRON Corporation CX-Programmer Affected: Ver.9.79 and earlier
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T10:07:05.975Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU92877622/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-22317",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-17T15:33:38.630665Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-17T15:34:00.712Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CX-Programmer",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.9.79 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22277 and CVE-2023-22314."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Use after free",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-03T13:07:10.073Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://jvn.jp/en/vu/JVNVU92877622/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2023-22317",
        "datePublished": "2023-08-03T12:56:14.503Z",
        "dateReserved": "2022-12-27T15:57:55.084Z",
        "dateUpdated": "2024-10-17T15:34:00.712Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-22314 (GCVE-0-2023-22314)

    Vulnerability from nvd – Published: 2023-08-03 12:59 – Updated: 2024-10-17 14:27
    VLAI
    Summary
    Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22277 and CVE-2023-22317.
    Severity
    No CVSS data available.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-17 14:27 UTC
    CWE
    • Use after free
    References
    Impacted products
    Vendor Product Version
    OMRON Corporation CX-Programmer Affected: Ver.9.79 and earlier
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T10:07:05.897Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU92877622/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-22314",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-17T14:27:26.735010Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-17T14:27:35.927Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CX-Programmer",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.9.79 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22277 and CVE-2023-22317."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Use after free",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-03T13:08:22.396Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://jvn.jp/en/vu/JVNVU92877622/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2023-22314",
        "datePublished": "2023-08-03T12:59:07.012Z",
        "dateReserved": "2022-12-27T15:57:55.088Z",
        "dateUpdated": "2024-10-17T14:27:35.927Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-38748 (GCVE-0-2023-38748)

    Vulnerability from nvd – Published: 2023-08-03 05:09 – Updated: 2024-10-17 15:44
    VLAI
    Summary
    Use after free vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur.
    Severity
    No CVSS data available.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-17 15:44 UTC
    CWE
    • Use after free
    Impacted products
    Vendor Product Version
    OMRON Corporation CX-Programmer Affected: Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T17:54:38.363Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.ia.omron.com/product/vulnerability/OMSR-2023-005_en.pdf"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU93286117/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-38748",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-17T15:44:38.294238Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-17T15:44:46.018Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CX-Programmer",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Use after free vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Use after free",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-03T05:09:16.186Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://www.ia.omron.com/product/vulnerability/OMSR-2023-005_en.pdf"
            },
            {
              "url": "https://jvn.jp/en/vu/JVNVU93286117/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2023-38748",
        "datePublished": "2023-08-03T05:09:16.186Z",
        "dateReserved": "2023-07-25T03:13:53.096Z",
        "dateUpdated": "2024-10-17T15:44:46.018Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-38747 (GCVE-0-2023-38747)

    Vulnerability from nvd – Published: 2023-08-03 05:00 – Updated: 2024-10-21 19:34
    VLAI
    Summary
    Heap-based buffer overflow vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur.
    Severity
    No CVSS data available.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-21 19:33 UTC
    CWE
    • Heap-based buffer overflow
    Impacted products
    Vendor Product Version
    OMRON Corporation CX-Programmer Affected: Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T17:54:38.311Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.ia.omron.com/product/vulnerability/OMSR-2023-005_en.pdf"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU93286117/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-38747",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-21T19:33:15.295856Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-21T19:34:50.342Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CX-Programmer",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Heap-based buffer overflow vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Heap-based buffer overflow",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-03T05:00:34.672Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://www.ia.omron.com/product/vulnerability/OMSR-2023-005_en.pdf"
            },
            {
              "url": "https://jvn.jp/en/vu/JVNVU93286117/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2023-38747",
        "datePublished": "2023-08-03T05:00:34.672Z",
        "dateReserved": "2023-07-25T03:13:53.096Z",
        "dateUpdated": "2024-10-21T19:34:50.342Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-38746 (GCVE-0-2023-38746)

    Vulnerability from nvd – Published: 2023-08-03 04:58 – Updated: 2024-10-17 15:03
    VLAI
    Summary
    Out-of-bounds read vulnerability/issue exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur.
    Severity
    No CVSS data available.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-17 15:02 UTC
    CWE
    • Out-of-bounds read
    Impacted products
    Vendor Product Version
    OMRON Corporation CX-Programmer Affected: Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T17:54:38.524Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.ia.omron.com/product/vulnerability/OMSR-2023-005_en.pdf"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU93286117/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-38746",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-17T15:02:40.370304Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-17T15:03:39.363Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CX-Programmer",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Out-of-bounds read vulnerability/issue exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Out-of-bounds read",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-03T04:58:30.228Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://www.ia.omron.com/product/vulnerability/OMSR-2023-005_en.pdf"
            },
            {
              "url": "https://jvn.jp/en/vu/JVNVU93286117/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2023-38746",
        "datePublished": "2023-08-03T04:58:30.228Z",
        "dateReserved": "2023-07-25T03:13:53.096Z",
        "dateUpdated": "2024-10-17T15:03:39.363Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-27385 (GCVE-0-2023-27385)

    Vulnerability from nvd – Published: 2023-05-10 00:00 – Updated: 2025-01-28 14:23
    VLAI
    Summary
    Heap-based buffer overflow vulnerability exists in CX-Drive All models all versions. By having a user open a specially crafted SDD file, arbitrary code may be executed and/or information may be disclosed.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-01-28 14:23 UTC
    CWE
    • Buffer overflow
    • CWE-787 - Out-of-bounds Write
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T12:09:43.373Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.ia.omron.com/product/vulnerability/OMSR-2023-004_en.pdf"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU97372625/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-27385",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-01-28T14:23:03.703347Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-787",
                    "description": "CWE-787 Out-of-bounds Write",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-01-28T14:23:09.034Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CX-Drive All models",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Heap-based buffer overflow vulnerability exists in CX-Drive All models all versions. By having a user open a specially crafted SDD file, arbitrary code may be executed and/or information may be disclosed.\r\n"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Buffer overflow",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-02T10:54:24.555Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://www.ia.omron.com/product/vulnerability/OMSR-2023-004_en.pdf"
            },
            {
              "url": "https://jvn.jp/en/vu/JVNVU97372625/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2023-27385",
        "datePublished": "2023-05-10T00:00:00.000Z",
        "dateReserved": "2023-03-15T00:00:00.000Z",
        "dateUpdated": "2025-01-28T14:23:09.034Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-22322 (GCVE-0-2023-22322)

    Vulnerability from nvd – Published: 2023-01-30 00:00 – Updated: 2025-03-27 20:17
    VLAI
    Summary
    Improper restriction of XML external entity reference (XXE) vulnerability exists in OMRON CX-Motion Pro 1.4.6.013 and earlier. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Motion Pro is installed may be disclosed.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-03-27 20:16 UTC
    CWE
    • XML external entities (XXE)
    • CWE-611 - Improper Restriction of XML External Entity Reference
    References
    Impacted products
    Vendor Product Version
    OMRON Corporation CX-Motion Pro Affected: 1.4.6.013 and earlier
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T10:07:05.987Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU94200979/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "NONE",
                  "baseScore": 5.5,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-22322",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-03-27T20:16:36.548819Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-611",
                    "description": "CWE-611 Improper Restriction of XML External Entity Reference",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-03-27T20:17:03.881Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CX-Motion Pro",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.4.6.013 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Improper restriction of XML external entity reference (XXE) vulnerability exists in OMRON CX-Motion Pro 1.4.6.013 and earlier. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Motion Pro is installed may be disclosed."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "XML external entities (XXE)",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-01-30T00:00:00.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://jvn.jp/en/vu/JVNVU94200979/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2023-22322",
        "datePublished": "2023-01-30T00:00:00.000Z",
        "dateReserved": "2022-12-28T00:00:00.000Z",
        "dateUpdated": "2025-03-27T20:17:03.881Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-46282 (GCVE-0-2022-46282)

    Vulnerability from nvd – Published: 2022-12-21 00:00 – Updated: 2025-04-16 16:04
    VLAI
    Summary
    Use after free vulnerability in CX-Drive V3.00 and earlier allows a local attacker to execute arbitrary code by having a user to open a specially crafted file,
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-16 16:03 UTC
    CWE
    • Use After Free
    • CWE-416 - Use After Free
    References
    Impacted products
    Vendor Product Version
    OMRON Corporation CX-Drive Affected: V3.00 and earlier
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T14:31:44.424Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU92689335/index.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-46282",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-16T16:03:50.064948Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-416",
                    "description": "CWE-416 Use After Free",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-16T16:04:18.711Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CX-Drive",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "V3.00 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Use after free vulnerability in CX-Drive V3.00 and earlier allows a local attacker to execute arbitrary code by having a user to open a specially crafted file,"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Use After Free",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-12-21T00:00:00.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://jvn.jp/en/vu/JVNVU92689335/index.html"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2022-46282",
        "datePublished": "2022-12-21T00:00:00.000Z",
        "dateReserved": "2022-12-06T00:00:00.000Z",
        "dateUpdated": "2025-04-16T16:04:18.711Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-43667 (GCVE-0-2022-43667)

    Vulnerability from nvd – Published: 2022-12-07 00:00 – Updated: 2025-04-23 14:09
    VLAI
    Summary
    Stack-based buffer overflow vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-23 14:08 UTC
    CWE
    • Stack-based Buffer Overflow
    • CWE-787 - Out-of-bounds Write
    Impacted products
    Vendor Product Version
    OMRON Corporation CX-Programmer Affected: v.9.77 and earlier
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T13:40:05.992Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU92877622/index.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/vu/JVNVU92877622/index.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-43667",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-23T14:08:22.472874Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-787",
                    "description": "CWE-787 Out-of-bounds Write",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-23T14:09:01.756Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CX-Programmer",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "v.9.77 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Stack-based buffer overflow vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Stack-based Buffer Overflow",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-12-07T00:00:00.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://jvn.jp/en/vu/JVNVU92877622/index.html"
            },
            {
              "url": "https://jvn.jp/vu/JVNVU92877622/index.html"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2022-43667",
        "datePublished": "2022-12-07T00:00:00.000Z",
        "dateReserved": "2022-10-22T00:00:00.000Z",
        "dateUpdated": "2025-04-23T14:09:01.756Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-43509 (GCVE-0-2022-43509)

    Vulnerability from nvd – Published: 2022-12-07 00:00 – Updated: 2025-04-23 14:18
    VLAI
    Summary
    Out-of-bounds write vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-23 14:17 UTC
    CWE
    • Out-of-bounds Write
    • CWE-787 - Out-of-bounds Write
    Impacted products
    Vendor Product Version
    OMRON Corporation CX-Programmer Affected: v.9.77 and earlier
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T13:32:59.641Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU92877622/index.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/vu/JVNVU92877622/index.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-43509",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-23T14:17:47.602031Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-787",
                    "description": "CWE-787 Out-of-bounds Write",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-23T14:18:24.192Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CX-Programmer",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "v.9.77 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Out-of-bounds write vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Out-of-bounds Write",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-12-07T00:00:00.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://jvn.jp/en/vu/JVNVU92877622/index.html"
            },
            {
              "url": "https://jvn.jp/vu/JVNVU92877622/index.html"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2022-43509",
        "datePublished": "2022-12-07T00:00:00.000Z",
        "dateReserved": "2022-10-22T00:00:00.000Z",
        "dateUpdated": "2025-04-23T14:18:24.192Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-43508 (GCVE-0-2022-43508)

    Vulnerability from nvd – Published: 2022-12-07 00:00 – Updated: 2025-04-23 14:46
    VLAI
    Summary
    Use-after free vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-23 14:44 UTC
    CWE
    • Use-after-free
    • CWE-416 - Use After Free
    Impacted products
    Vendor Product Version
    OMRON Corporation CX-Programmer Affected: v.9.77 and earlier
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T13:32:59.342Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU92877622/index.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/vu/JVNVU92877622/index.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-43508",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-23T14:44:19.369346Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-416",
                    "description": "CWE-416 Use After Free",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-23T14:46:05.306Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CX-Programmer",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "v.9.77 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Use-after free vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Use-after-free",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-12-07T00:00:00.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://jvn.jp/en/vu/JVNVU92877622/index.html"
            },
            {
              "url": "https://jvn.jp/vu/JVNVU92877622/index.html"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2022-43508",
        "datePublished": "2022-12-07T00:00:00.000Z",
        "dateReserved": "2022-10-22T00:00:00.000Z",
        "dateUpdated": "2025-04-23T14:46:05.306Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-31412 (GCVE-0-2024-31412)

    Vulnerability from cvelistv5 – Published: 2024-05-01 12:52 – Updated: 2024-08-02 01:52
    VLAI
    Summary
    Out-of-bounds read vulnerability exists in CX-Programmer included in CX-One CXONE-AL[][]D-V4 Ver. 9.81 or lower. Opening a specially crafted project file may lead to information disclosure and/or the product being crashed.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-25 14:29 UTC
    CWE
    • Out-of-bounds read
    • CWE-125 - Out-of-bounds Read
    Impacted products
    Vendor Product Version
    OMRON Corporation CX-Programmer Affected: Included in CX-One CXONE-AL[][]D-V4 Ver. 9.81 or lower
    Create a notification for this product.
    omron cx-programmer Affected: 0 , ≤ 9.81 (custom)
        cpe:2.3:a:omron:cx-programmer:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:omron:cx-programmer:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "cx-programmer",
                "vendor": "omron",
                "versions": [
                  {
                    "lessThanOrEqual": "9.81",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-31412",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-25T14:29:07.641532Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-125",
                    "description": "CWE-125 Out-of-bounds Read",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-25T14:36:05.441Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T01:52:56.842Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2024-003_en.pdf"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU98274902/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CX-Programmer",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Included in CX-One CXONE-AL[][]D-V4 Ver. 9.81 or lower"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Out-of-bounds read vulnerability exists in CX-Programmer included in CX-One CXONE-AL[][]D-V4 Ver. 9.81 or lower. Opening a specially crafted project file may lead to information disclosure and/or the product being crashed."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Out-of-bounds read",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-05-01T12:52:13.173Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2024-003_en.pdf"
            },
            {
              "url": "https://jvn.jp/en/vu/JVNVU98274902/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2024-31412",
        "datePublished": "2024-05-01T12:52:13.173Z",
        "dateReserved": "2024-04-03T10:57:10.684Z",
        "dateUpdated": "2024-08-02T01:52:56.842Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-27121 (GCVE-0-2024-27121)

    Vulnerability from cvelistv5 – Published: 2024-03-12 07:55 – Updated: 2024-08-16 19:50
    VLAI
    Summary
    Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary file in the affected product may be accessed or arbitrary code may be executed by processing a specially crafted request sent from a remote attacker with an administrative privilege. As for the details of the affected product names/versions, see the information provided by the vendor under [References] section.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-12 18:25 UTC
    CWE
    • Path traversal
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    OMRON Corporation Machine Automation Controller NJ Series Affected: NJ101-[][][][] Ver.1.64.03 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NJ Series Affected: NJ301-[][][][] Ver.1.64.00 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NJ Series Affected: NJ501-1[]0[] Ver.1.64.03 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NJ Series Affected: NJ501-1[]2[] Ver.1.64.00 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NJ Series Affected: NJ501-1340 Ver.1.64.00 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NJ Series Affected: NJ501-4[][][] Ver.1.64.00 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NJ Series Affected: NJ501-5300 Ver.1.64.00 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NJ Series Affected: NJ501-R[][][] Ver.1.64.00 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NX Series Affected: NX1P2-[][][][][][] Ver.1.64.00 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NX Series Affected: NX1P2-[][][][][][]1 Ver.1.64.00 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NX Series Affected: NX102-[][][][] Ver.1.64.00 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NX Series Affected: NX502-[][][][] Ver.1.65.01 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NX Series Affected: NX701-[][][][] Ver.1.35.00 and earlier
    Create a notification for this product.
    OMRON Corporation Machine Automation Controller NX Series Affected: NX-EIP201 Ver.1.00.01 and earlier
    Create a notification for this product.
    omron nj101-9020_firmware Affected: 0 , ≤ 1.64.03 (custom)
        cpe:2.3:o:omron:nj101-1000_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj101-1020_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj101-9000_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj101-9020_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    omron nj301-1200_firmware Affected: 0 , ≤ 1.64.00 (custom)
        cpe:2.3:o:omron:nj301-1100_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj301-1200_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    omron nj501-r520_firmware Affected: 0 , ≤ 1.64.00 (custom)
        cpe:2.3:o:omron:nj501-1300_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-1320_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-1340_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-1400_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-1420_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-1500_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-1520_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-4300_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-4310_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-4320_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-4400_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-4500_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-5300_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-r300_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-r320_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-r400_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-r420_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-r500_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:omron:nj501-r520_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T00:27:59.260Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2024-001_en.pdf"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.fa.omron.co.jp/product/security/assets/pdf/ja/OMSR-2024-001_ja.pdf"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU95852116/index.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:omron:nj101-1000_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj101-1020_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj101-9000_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj101-9020_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "nj101-9020_firmware",
                "vendor": "omron",
                "versions": [
                  {
                    "lessThanOrEqual": "1.64.03",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:omron:nj301-1100_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj301-1200_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "nj301-1200_firmware",
                "vendor": "omron",
                "versions": [
                  {
                    "lessThanOrEqual": "1.64.00",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:omron:nj501-1300_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-1320_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-1340_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-1400_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-1420_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-1500_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-1520_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-4300_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-4310_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-4320_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-4400_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-4500_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-5300_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-r300_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-r320_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-r400_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-r420_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-r500_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:omron:nj501-r520_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "nj501-r520_firmware",
                "vendor": "omron",
                "versions": [
                  {
                    "lessThanOrEqual": "1.64.00",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.2,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "HIGH",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-27121",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-12T18:25:40.523309Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-22",
                    "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-16T19:50:12.016Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Machine Automation Controller NJ Series ",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NJ101-[][][][] Ver.1.64.03 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NJ Series ",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NJ301-[][][][] Ver.1.64.00 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NJ Series ",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NJ501-1[]0[] Ver.1.64.03 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NJ Series ",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NJ501-1[]2[] Ver.1.64.00 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NJ Series ",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NJ501-1340 Ver.1.64.00 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NJ Series ",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NJ501-4[][][] Ver.1.64.00 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NJ Series ",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NJ501-5300 Ver.1.64.00 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NJ Series ",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NJ501-R[][][] Ver.1.64.00 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NX Series",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NX1P2-[][][][][][] Ver.1.64.00 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NX Series",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NX1P2-[][][][][][]1 Ver.1.64.00 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NX Series",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NX102-[][][][] Ver.1.64.00 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NX Series",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NX502-[][][][] Ver.1.65.01 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NX Series",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NX701-[][][][] Ver.1.35.00 and earlier "
                }
              ]
            },
            {
              "product": "Machine Automation Controller NX Series",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "NX-EIP201 Ver.1.00.01 and earlier "
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary file in the affected product may be accessed or arbitrary code may be executed by processing a specially crafted request sent from a remote attacker with an administrative privilege. As for the details of the affected product names/versions, see the information provided by the vendor under [References] section."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Path traversal",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-12T07:55:48.301Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2024-001_en.pdf"
            },
            {
              "url": "https://www.fa.omron.co.jp/product/security/assets/pdf/ja/OMSR-2024-001_ja.pdf"
            },
            {
              "url": "https://jvn.jp/en/vu/JVNVU95852116/index.html"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2024-27121",
        "datePublished": "2024-03-12T07:55:48.301Z",
        "dateReserved": "2024-02-20T08:22:05.133Z",
        "dateUpdated": "2024-08-16T19:50:12.016Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-45792 (GCVE-0-2022-45792)

    Vulnerability from cvelistv5 – Published: 2024-01-22 17:46 – Updated: 2025-06-17 21:19
    VLAI
    Title
    Directory Traversal in Project File Format allows overwrite (Zip Slip)
    Summary
    Project files may contain malicious contents which the software will use to create files on the filesystem. This allows directory traversal and overwriting files with the privileges of the logged-in user.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-01-30 18:36 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    Omron Sysmac Studio Affected: 0 , < 1.54.0 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T14:17:04.101Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.dragos.com/advisory/omron-plc-and-engineering-software-network-and-file-format-access/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-45792",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-01-30T18:36:27.204028Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-06-17T21:19:25.577Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows",
                "x86",
                "64 bit"
              ],
              "product": "Sysmac Studio",
              "vendor": "Omron",
              "versions": [
                {
                  "lessThan": "1.54.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Project files may contain malicious contents which the software will use to create files on the filesystem. This allows directory traversal and overwriting files with the privileges of the logged-in user."
                }
              ],
              "value": "Project files may contain malicious contents which the software will use to create files on the filesystem. This allows directory traversal and overwriting files with the privileges of the logged-in user."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-165",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-165 File Manipulation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-22T17:46:36.699Z",
            "orgId": "12bdf821-1545-4a87-aac5-61670cc6fcef",
            "shortName": "Dragos"
          },
          "references": [
            {
              "url": "https://www.dragos.com/advisory/omron-plc-and-engineering-software-network-and-file-format-access/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Directory Traversal in Project File Format allows overwrite (Zip Slip)",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "12bdf821-1545-4a87-aac5-61670cc6fcef",
        "assignerShortName": "Dragos",
        "cveId": "CVE-2022-45792",
        "datePublished": "2024-01-22T17:46:36.699Z",
        "dateReserved": "2022-11-22T17:52:43.198Z",
        "dateUpdated": "2025-06-17T21:19:25.577Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-45793 (GCVE-0-2022-45793)

    Vulnerability from cvelistv5 – Published: 2024-01-10 20:49 – Updated: 2025-04-17 15:42
    VLAI
    Title
    Executable files writable by low-privileged users in Omron Sysmac Studio
    Summary
    Sysmac Studio installs executables in a directory with poor permissions. This can allow a locally-authenticated attacker to overwrite files which will result in code execution with privileges of a different user.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-01-11 19:43 UTC
    CWE
    • CWE-276 - Incorrect Default Permissions
    Impacted products
    Vendor Product Version
    Omron Sysmac Studio Affected: 0 , ≤ 1.54.0 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T14:17:04.086Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-262-04"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.dragos.com/advisory/omron-plc-and-engineering-software-network-and-file-format-access/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2023-009_en.pdf"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-45793",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-01-11T19:43:03.624295Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-17T15:42:42.580Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "platforms": [
                "Windows",
                "64 bit",
                "32 bit"
              ],
              "product": "Sysmac Studio",
              "vendor": "Omron",
              "versions": [
                {
                  "lessThanOrEqual": "1.54.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Reid Wightman of Dragos"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Sysmac Studio installs executables in a directory with poor permissions. This can allow a locally-authenticated attacker to overwrite files which will result in code execution with privileges of a different user."
                }
              ],
              "value": "Sysmac Studio installs executables in a directory with poor permissions. This can allow a locally-authenticated attacker to overwrite files which will result in code execution with privileges of a different user."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-558",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-558 Replace Trusted Executable"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-276",
                  "description": "CWE-276 Incorrect Default Permissions",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-22T16:32:24.144Z",
            "orgId": "12bdf821-1545-4a87-aac5-61670cc6fcef",
            "shortName": "Dragos"
          },
          "references": [
            {
              "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-262-04"
            },
            {
              "url": "https://www.dragos.com/advisory/omron-plc-and-engineering-software-network-and-file-format-access/"
            },
            {
              "url": "https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2023-009_en.pdf"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Executable files writable by low-privileged users in Omron Sysmac Studio",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "12bdf821-1545-4a87-aac5-61670cc6fcef",
        "assignerShortName": "Dragos",
        "cveId": "CVE-2022-45793",
        "datePublished": "2024-01-10T20:49:36.082Z",
        "dateReserved": "2022-11-22T17:52:43.199Z",
        "dateUpdated": "2025-04-17T15:42:42.580Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-22277 (GCVE-0-2023-22277)

    Vulnerability from cvelistv5 – Published: 2023-08-03 13:05 – Updated: 2024-10-17 14:21
    VLAI
    Summary
    Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22317 and CVE-2023-22314.
    Severity
    No CVSS data available.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-17 14:21 UTC
    CWE
    • Use after free
    References
    Impacted products
    Vendor Product Version
    OMRON Corporation CX-Programmer Affected: Ver.9.79 and earlier
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T10:07:05.433Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU92877622/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-22277",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-17T14:21:26.727465Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-17T14:21:36.037Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CX-Programmer",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.9.79 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22317 and CVE-2023-22314."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Use after free",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-03T13:05:45.204Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://jvn.jp/en/vu/JVNVU92877622/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2023-22277",
        "datePublished": "2023-08-03T13:05:45.204Z",
        "dateReserved": "2022-12-27T15:57:55.077Z",
        "dateUpdated": "2024-10-17T14:21:36.037Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-22314 (GCVE-0-2023-22314)

    Vulnerability from cvelistv5 – Published: 2023-08-03 12:59 – Updated: 2024-10-17 14:27
    VLAI
    Summary
    Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22277 and CVE-2023-22317.
    Severity
    No CVSS data available.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-17 14:27 UTC
    CWE
    • Use after free
    References
    Impacted products
    Vendor Product Version
    OMRON Corporation CX-Programmer Affected: Ver.9.79 and earlier
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T10:07:05.897Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU92877622/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-22314",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-17T14:27:26.735010Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-17T14:27:35.927Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CX-Programmer",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.9.79 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22277 and CVE-2023-22317."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Use after free",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-03T13:08:22.396Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://jvn.jp/en/vu/JVNVU92877622/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2023-22314",
        "datePublished": "2023-08-03T12:59:07.012Z",
        "dateReserved": "2022-12-27T15:57:55.088Z",
        "dateUpdated": "2024-10-17T14:27:35.927Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-22317 (GCVE-0-2023-22317)

    Vulnerability from cvelistv5 – Published: 2023-08-03 12:56 – Updated: 2024-10-17 15:34
    VLAI
    Summary
    Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22277 and CVE-2023-22314.
    Severity
    No CVSS data available.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-17 15:33 UTC
    CWE
    • Use after free
    References
    Impacted products
    Vendor Product Version
    OMRON Corporation CX-Programmer Affected: Ver.9.79 and earlier
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T10:07:05.975Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU92877622/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-22317",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-17T15:33:38.630665Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-17T15:34:00.712Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CX-Programmer",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.9.79 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22277 and CVE-2023-22314."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Use after free",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-03T13:07:10.073Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://jvn.jp/en/vu/JVNVU92877622/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2023-22317",
        "datePublished": "2023-08-03T12:56:14.503Z",
        "dateReserved": "2022-12-27T15:57:55.084Z",
        "dateUpdated": "2024-10-17T15:34:00.712Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-38748 (GCVE-0-2023-38748)

    Vulnerability from cvelistv5 – Published: 2023-08-03 05:09 – Updated: 2024-10-17 15:44
    VLAI
    Summary
    Use after free vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur.
    Severity
    No CVSS data available.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-17 15:44 UTC
    CWE
    • Use after free
    Impacted products
    Vendor Product Version
    OMRON Corporation CX-Programmer Affected: Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T17:54:38.363Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.ia.omron.com/product/vulnerability/OMSR-2023-005_en.pdf"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU93286117/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-38748",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-17T15:44:38.294238Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-17T15:44:46.018Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CX-Programmer",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Use after free vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Use after free",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-03T05:09:16.186Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://www.ia.omron.com/product/vulnerability/OMSR-2023-005_en.pdf"
            },
            {
              "url": "https://jvn.jp/en/vu/JVNVU93286117/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2023-38748",
        "datePublished": "2023-08-03T05:09:16.186Z",
        "dateReserved": "2023-07-25T03:13:53.096Z",
        "dateUpdated": "2024-10-17T15:44:46.018Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-38747 (GCVE-0-2023-38747)

    Vulnerability from cvelistv5 – Published: 2023-08-03 05:00 – Updated: 2024-10-21 19:34
    VLAI
    Summary
    Heap-based buffer overflow vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur.
    Severity
    No CVSS data available.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-21 19:33 UTC
    CWE
    • Heap-based buffer overflow
    Impacted products
    Vendor Product Version
    OMRON Corporation CX-Programmer Affected: Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T17:54:38.311Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.ia.omron.com/product/vulnerability/OMSR-2023-005_en.pdf"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU93286117/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-38747",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-21T19:33:15.295856Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-21T19:34:50.342Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CX-Programmer",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Heap-based buffer overflow vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Heap-based buffer overflow",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-03T05:00:34.672Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://www.ia.omron.com/product/vulnerability/OMSR-2023-005_en.pdf"
            },
            {
              "url": "https://jvn.jp/en/vu/JVNVU93286117/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2023-38747",
        "datePublished": "2023-08-03T05:00:34.672Z",
        "dateReserved": "2023-07-25T03:13:53.096Z",
        "dateUpdated": "2024-10-21T19:34:50.342Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-38746 (GCVE-0-2023-38746)

    Vulnerability from cvelistv5 – Published: 2023-08-03 04:58 – Updated: 2024-10-17 15:03
    VLAI
    Summary
    Out-of-bounds read vulnerability/issue exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur.
    Severity
    No CVSS data available.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-17 15:02 UTC
    CWE
    • Out-of-bounds read
    Impacted products
    Vendor Product Version
    OMRON Corporation CX-Programmer Affected: Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T17:54:38.524Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.ia.omron.com/product/vulnerability/OMSR-2023-005_en.pdf"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU93286117/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-38746",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-17T15:02:40.370304Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-17T15:03:39.363Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CX-Programmer",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Out-of-bounds read vulnerability/issue exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Out-of-bounds read",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-03T04:58:30.228Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://www.ia.omron.com/product/vulnerability/OMSR-2023-005_en.pdf"
            },
            {
              "url": "https://jvn.jp/en/vu/JVNVU93286117/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2023-38746",
        "datePublished": "2023-08-03T04:58:30.228Z",
        "dateReserved": "2023-07-25T03:13:53.096Z",
        "dateUpdated": "2024-10-17T15:03:39.363Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-27385 (GCVE-0-2023-27385)

    Vulnerability from cvelistv5 – Published: 2023-05-10 00:00 – Updated: 2025-01-28 14:23
    VLAI
    Summary
    Heap-based buffer overflow vulnerability exists in CX-Drive All models all versions. By having a user open a specially crafted SDD file, arbitrary code may be executed and/or information may be disclosed.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-01-28 14:23 UTC
    CWE
    • Buffer overflow
    • CWE-787 - Out-of-bounds Write
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T12:09:43.373Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.ia.omron.com/product/vulnerability/OMSR-2023-004_en.pdf"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU97372625/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-27385",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-01-28T14:23:03.703347Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-787",
                    "description": "CWE-787 Out-of-bounds Write",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-01-28T14:23:09.034Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CX-Drive All models",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Heap-based buffer overflow vulnerability exists in CX-Drive All models all versions. By having a user open a specially crafted SDD file, arbitrary code may be executed and/or information may be disclosed.\r\n"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Buffer overflow",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-08-02T10:54:24.555Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://www.ia.omron.com/product/vulnerability/OMSR-2023-004_en.pdf"
            },
            {
              "url": "https://jvn.jp/en/vu/JVNVU97372625/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2023-27385",
        "datePublished": "2023-05-10T00:00:00.000Z",
        "dateReserved": "2023-03-15T00:00:00.000Z",
        "dateUpdated": "2025-01-28T14:23:09.034Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-22322 (GCVE-0-2023-22322)

    Vulnerability from cvelistv5 – Published: 2023-01-30 00:00 – Updated: 2025-03-27 20:17
    VLAI
    Summary
    Improper restriction of XML external entity reference (XXE) vulnerability exists in OMRON CX-Motion Pro 1.4.6.013 and earlier. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Motion Pro is installed may be disclosed.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-03-27 20:16 UTC
    CWE
    • XML external entities (XXE)
    • CWE-611 - Improper Restriction of XML External Entity Reference
    References
    Impacted products
    Vendor Product Version
    OMRON Corporation CX-Motion Pro Affected: 1.4.6.013 and earlier
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T10:07:05.987Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU94200979/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "NONE",
                  "baseScore": 5.5,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-22322",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-03-27T20:16:36.548819Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-611",
                    "description": "CWE-611 Improper Restriction of XML External Entity Reference",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-03-27T20:17:03.881Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CX-Motion Pro",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.4.6.013 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Improper restriction of XML external entity reference (XXE) vulnerability exists in OMRON CX-Motion Pro 1.4.6.013 and earlier. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Motion Pro is installed may be disclosed."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "XML external entities (XXE)",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-01-30T00:00:00.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://jvn.jp/en/vu/JVNVU94200979/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2023-22322",
        "datePublished": "2023-01-30T00:00:00.000Z",
        "dateReserved": "2022-12-28T00:00:00.000Z",
        "dateUpdated": "2025-03-27T20:17:03.881Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-46282 (GCVE-0-2022-46282)

    Vulnerability from cvelistv5 – Published: 2022-12-21 00:00 – Updated: 2025-04-16 16:04
    VLAI
    Summary
    Use after free vulnerability in CX-Drive V3.00 and earlier allows a local attacker to execute arbitrary code by having a user to open a specially crafted file,
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-16 16:03 UTC
    CWE
    • Use After Free
    • CWE-416 - Use After Free
    References
    Impacted products
    Vendor Product Version
    OMRON Corporation CX-Drive Affected: V3.00 and earlier
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T14:31:44.424Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU92689335/index.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-46282",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-16T16:03:50.064948Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-416",
                    "description": "CWE-416 Use After Free",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-16T16:04:18.711Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CX-Drive",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "V3.00 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Use after free vulnerability in CX-Drive V3.00 and earlier allows a local attacker to execute arbitrary code by having a user to open a specially crafted file,"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Use After Free",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-12-21T00:00:00.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://jvn.jp/en/vu/JVNVU92689335/index.html"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2022-46282",
        "datePublished": "2022-12-21T00:00:00.000Z",
        "dateReserved": "2022-12-06T00:00:00.000Z",
        "dateUpdated": "2025-04-16T16:04:18.711Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-43667 (GCVE-0-2022-43667)

    Vulnerability from cvelistv5 – Published: 2022-12-07 00:00 – Updated: 2025-04-23 14:09
    VLAI
    Summary
    Stack-based buffer overflow vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-23 14:08 UTC
    CWE
    • Stack-based Buffer Overflow
    • CWE-787 - Out-of-bounds Write
    Impacted products
    Vendor Product Version
    OMRON Corporation CX-Programmer Affected: v.9.77 and earlier
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T13:40:05.992Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU92877622/index.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/vu/JVNVU92877622/index.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-43667",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-23T14:08:22.472874Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-787",
                    "description": "CWE-787 Out-of-bounds Write",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-23T14:09:01.756Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CX-Programmer",
              "vendor": "OMRON Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "v.9.77 and earlier"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Stack-based buffer overflow vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Stack-based Buffer Overflow",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-12-07T00:00:00.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://jvn.jp/en/vu/JVNVU92877622/index.html"
            },
            {
              "url": "https://jvn.jp/vu/JVNVU92877622/index.html"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2022-43667",
        "datePublished": "2022-12-07T00:00:00.000Z",
        "dateReserved": "2022-10-22T00:00:00.000Z",
        "dateUpdated": "2025-04-23T14:09:01.756Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }