[Japanese] | |
JVNDB-2025-001016 | |
OMRON NJ/NX series vulnerable to path traversal | |
Overview | |
Machine Automation Controller NJ/NX series provided by OMRON Corporation contain a path traversal vulnerability (CWE-22, CVE-2024-12083). | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 6.6 (Medium) [Other]
| |
Affected Products | |
| |
OMRON Corporation | |
Refer to the developer's advisory "Appendix" section regarding how to check the affected versions. (*1) Refer to "ID Information Indication" section of the manual "NJ-series CPU unit Hardware User's Manual (W500)" regarding how to check Lot No. (*2) Refer to "ID Information Indication" section of the manual "NX1P2 CPU Unit User's Manual (Hardware) (W578)" regarding how to check Lot No. As for the details, refer to the information provided by the developer. | |
Impact | |
An arbitrary file in the affected product may be accessed or arbitrary code may be executed by processing a specially crafted request sent from a remote attacker with an administrative privilege. | |
Solution | |
[Update the software] | |
Vendor Information | |
OMRON Corporation | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2025/01/14 |
Date First Published | 2025/02/06 |
Date Last Updated | 2025/02/06 |