8.1
CVE-2022-33208
- EPSS 0.09%
- Published 04.07.2022 02:15:07
- Last modified 21.11.2024 07:07:43
- Source vultures@jpcert.or.jp
- Teams watchlist Login
- Open Login
Authentication bypass by capture-replay vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, Automation software 'Sysmac Studio' all models V1.49 and earlier, and Programmable Terminal (PT) NA series NA5-15W/NA5-12W/NA5-9W/NA5-7W models Runtime V1.15 and earlier, which may allow a remote attacker who can analyze the communication between the affected controller and automation software 'Sysmac Studio' and/or a Programmable Terminal (PT) to access the controller.
Data is provided by the National Vulnerability Database (NVD)
Omron ≫ Nx701-1600 Firmware Version <= 1.28
Omron ≫ Nx701-1700 Firmware Version <= 1.28
Omron ≫ Nx701-z700 Firmware Version <= 1.28
Omron ≫ Nx701-z600 Firmware Version <= 1.28
Omron ≫ Nx701-1720 Firmware Version <= 1.28
Omron ≫ Nx701-1620 Firmware Version <= 1.28
Omron ≫ Nx102-1200 Firmware Version <= 1.48
Omron ≫ Nx102-1100 Firmware Version <= 1.48
Omron ≫ Nx102-1000 Firmware Version <= 1.48
Omron ≫ Nx102-1220 Firmware Version <= 1.48
Omron ≫ Nx102-1120 Firmware Version <= 1.48
Omron ≫ Nx102-1020 Firmware Version <= 1.48
Omron ≫ Nx102-9020 Firmware Version <= 1.48
Omron ≫ Nx1p2-1140dt Firmware Version <= 1.48
Omron ≫ Nx1p2-1140dt1 Firmware Version <= 1.48
Omron ≫ Nx1p2-1040dt Firmware Version <= 1.48
Omron ≫ Nx1p2-1040dt1 Firmware Version <= 1.48
Omron ≫ Nx1p2-9024dt Firmware Version <= 1.48
Omron ≫ Nx1p2-9024dt1 Firmware Version <= 1.48
Omron ≫ Nx1w-cif01 Firmware Version <= 1.48
Omron ≫ Nx1w-cif11 Firmware Version <= 1.48
Omron ≫ Nx1w-cif12 Firmware Version <= 1.48
Omron ≫ Nx1w-adb21 Firmware Version <= 1.48
Omron ≫ Nx1w-dab21v Firmware Version <= 1.48
Omron ≫ Nx1w-mab221 Firmware Version <= 1.48
Omron ≫ Nj501-1500 Firmware Version <= 1.48
Omron ≫ Nj501-140 Firmware Version <= 1.48
Omron ≫ Nj501-1300 Firmware Version <= 1.48
Omron ≫ Nj501-r500 Firmware Version <= 1.48
Omron ≫ Nj501-r520 Firmware Version <= 1.48
Omron ≫ Nj501-r400 Firmware Version <= 1.48
Omron ≫ Nj501-r420 Firmware Version <= 1.48
Omron ≫ Nj501-r300 Firmware Version <= 1.48
Omron ≫ Nj501-r320 Firmware Version <= 1.48
Omron ≫ Nj501-5300 Firmware Version <= 1.48
Omron ≫ Nj501-1520 Firmware Version <= 1.48
Omron ≫ Nj501-1420 Firmware Version <= 1.48
Omron ≫ Nj501-1320 Firmware Version <= 1.48
Omron ≫ Nj101-1020 Firmware Version <= 1.48
Omron ≫ Nj101-9020 Firmware Version <= 1.48
Omron ≫ Nj501-1340 Firmware Version <= 1.48
Omron ≫ Nj501-4500 Firmware Version <= 1.48
Omron ≫ Nj501-4400 Firmware Version <= 1.48
Omron ≫ Nj501-4300 Firmware Version <= 1.48
Omron ≫ Nj501-4310 Firmware Version <= 1.48
Omron ≫ Nj501-4320 Firmware Version <= 1.48
Omron ≫ Nj301-1200 Firmware Version < 1.48
Omron ≫ Nj301-1100 Firmware Version <= 1.48
Omron ≫ Nj101-1000 Firmware Version <= 1.48
Omron ≫ Nj101-9000 Firmware Version <= 1.48
Omron ≫ Nj-pa3001 Firmware Version <= 1.48
Omron ≫ Nj-pd3001 Firmware Version <= 1.48
Omron ≫ Sysmac Studio Version <= 1.49
Omron ≫ Na5-15w Firmware Version <= 1.15
Omron ≫ Na5-12w Firmware Version <= 1.15
Omron ≫ Na5-9w Firmware Version <= 1.15
Omron ≫ Na5-7w Firmware Version <= 1.15
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.09% | 0.269 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-294 Authentication Bypass by Capture-replay
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).