CVE-2015-0987
10.0 CRITICALOmron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmissi...
Published: 2015-10-06 · Last updated: 2026-06-02
Severity and scoring
- CVSS
- 10.0 CRITICAL
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:H
- CWE
- CWE-200, CWE-319
Affected products
| Vendor | Product |
|---|---|
| omron | cj2h_plc, cj2m_plc, cx-programmer |
Description
Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission, which allows remote attackers to obtain sensitive information by sniffing the network during a PLC unlock request.
Source: NVD
References
Related CVEs
Same vendor
- CVE-2022-34151 — Use of hard-coded credentials vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine auto... (8.1 HIGH)
- CVE-2022-33971 — Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Ma... (7.5 HIGH)
- CVE-2020-6986 — In all versions of Omron PLC CJ Series, an attacker can send a series of specific data packets within a short period, causing a service e... (7.5 HIGH)
- CVE-2019-18269 — Omron’s CS and CJ series PLCs have an unrestricted externally accessible lock vulnerability (9.8 CRITICAL)
- CVE-2019-13533 — In Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monitor traffic between the PLC and the co... (8.1 HIGH)
Same CWE
- CVE-2026-49219 — ImageMagick is free and open-source software used for editing and manipulating digital images (5.5 MEDIUM)
- CVE-2026-47165 — ImageMagick is free and open-source software used for editing and manipulating digital images (4.1 MEDIUM)
- CVE-2026-48855 — Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery
- CVE-2026-45329 — ESF-IDF is the Espressif Internet of Things (IOT) Development Framework (7.1 HIGH)
- CVE-2026-9741 — A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side Field Level Encryp... (6.5 MEDIUM)