7.5

CVE-2022-33971

Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, and Machine automation controller NJ series all models V 1.48 and earlier, which may allow an adjacent attacker who can analyze the communication between the controller and the specific software used by OMRON internally to cause a denial-of-service (DoS) condition or execute a malicious program.

Data is provided by the National Vulnerability Database (NVD)
OmronNx701-1600 Firmware Version <= 1.28
   OmronNx701-1600 Version-
OmronNx701-1700 Firmware Version <= 1.28
   OmronNx701-1700 Version-
OmronNx701-z700 Firmware Version <= 1.28
   OmronNx701-z700 Version-
OmronNx701-z600 Firmware Version <= 1.28
   OmronNx701-z600 Version-
OmronNx701-1720 Firmware Version <= 1.28
   OmronNx701-1720 Version-
OmronNx701-1620 Firmware Version <= 1.28
   OmronNx701-1620 Version-
OmronNx102-1200 Firmware Version <= 1.48
   OmronNx102-1200 Version-
OmronNx102-1100 Firmware Version <= 1.48
   OmronNx102-1100 Version-
OmronNx102-1000 Firmware Version <= 1.48
   OmronNx102-1000 Version-
OmronNx102-1220 Firmware Version <= 1.48
   OmronNx102-1220 Version-
OmronNx102-1120 Firmware Version <= 1.48
   OmronNx102-1120 Version-
OmronNx102-1020 Firmware Version <= 1.48
   OmronNx102-1020 Version-
OmronNx102-9020 Firmware Version <= 1.48
   OmronNx102-9020 Version-
OmronNx1p2-1140dt Firmware Version <= 1.48
   OmronNx1p2-1140dt Version-
OmronNx1p2-1140dt1 Firmware Version <= 1.48
   OmronNx1p2-1140dt1 Version-
OmronNx1p2-1040dt Firmware Version <= 1.48
   OmronNx1p2-1040dt Version-
OmronNx1p2-1040dt1 Firmware Version <= 1.48
   OmronNx1p2-1040dt1 Version-
OmronNx1p2-9024dt Firmware Version <= 1.48
   OmronNx1p2-9024dt Version-
OmronNx1p2-9024dt1 Firmware Version <= 1.48
   OmronNx1p2-9024dt1 Version-
OmronNx1w-cif01 Firmware Version <= 1.48
   OmronNx1w-cif01 Version-
OmronNx1w-cif11 Firmware Version <= 1.48
   OmronNx1w-cif11 Version-
OmronNx1w-cif12 Firmware Version <= 1.48
   OmronNx1w-cif12 Version-
OmronNx1w-adb21 Firmware Version <= 1.48
   OmronNx1w-adb21 Version-
OmronNx1w-dab21v Firmware Version <= 1.48
   OmronNx1w-dab21v Version-
OmronNx1w-mab221 Firmware Version <= 1.48
   OmronNx1w-mab221 Version-
OmronNj501-1500 Firmware Version <= 1.48
   OmronNj501-1500 Version-
OmronNj501-140 Firmware Version <= 1.48
   OmronNj501-140 Version-
OmronNj501-1300 Firmware Version <= 1.48
   OmronNj501-1300 Version-
OmronNj501-r500 Firmware Version <= 1.48
   OmronNj501-r500 Version-
OmronNj501-r520 Firmware Version <= 1.48
   OmronNj501-r520 Version-
OmronNj501-r400 Firmware Version <= 1.48
   OmronNj501-r400 Version-
OmronNj501-r420 Firmware Version <= 1.48
   OmronNj501-r420 Version-
OmronNj501-r300 Firmware Version <= 1.48
   OmronNj501-r300 Version-
OmronNj501-r320 Firmware Version <= 1.48
   OmronNj501-r320 Version-
OmronNj501-5300 Firmware Version <= 1.48
   OmronNj501-5300 Version-
OmronNj501-1520 Firmware Version <= 1.48
   OmronNj501-1520 Version-
OmronNj501-1420 Firmware Version <= 1.48
   OmronNj501-1420 Version-
OmronNj501-1320 Firmware Version <= 1.48
   OmronNj501-1320 Version-
OmronNj101-1020 Firmware Version <= 1.48
   OmronNj101-1020 Version-
OmronNj101-9020 Firmware Version <= 1.48
   OmronNj101-9020 Version-
OmronNj501-1340 Firmware Version <= 1.48
   OmronNj501-1340 Version-
OmronNj501-4500 Firmware Version <= 1.48
   OmronNj501-4500 Version-
OmronNj501-4400 Firmware Version <= 1.48
   OmronNj501-4400 Version-
OmronNj501-4300 Firmware Version <= 1.48
   OmronNj501-4300 Version-
OmronNj501-4310 Firmware Version <= 1.48
   OmronNj501-4310 Version-
OmronNj501-4320 Firmware Version <= 1.48
   OmronNj501-4320 Version-
OmronNj301-1200 Firmware Version < 1.48
   OmronNj301-1200 Version-
OmronNj301-1100 Firmware Version <= 1.48
   OmronNj301-1100 Version-
OmronNj101-1000 Firmware Version <= 1.48
   OmronNj101-1000 Version-
OmronNj101-9000 Firmware Version <= 1.48
   OmronNj101-9000 Version-
OmronNj-pa3001 Firmware Version <= 1.48
   OmronNj-pa3001 Version-
OmronNj-pd3001 Firmware Version <= 1.48
   OmronNj-pd3001 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.02% 0.042
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 1.6 5.9
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 5.4 5.5 6.4
AV:A/AC:M/Au:N/C:P/I:P/A:P
CWE-294 Authentication Bypass by Capture-replay

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).