QSearchQSearch

CVE-2015-0987

10.0 CRITICAL

Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmissi...

Published: 2015-10-06 · Last updated: 2026-06-02

Severity and scoring

CVSS
10.0 CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:H
CWE
CWE-200, CWE-319

Affected products

VendorProduct
omroncj2h_plc, cj2m_plc, cx-programmer

Description

Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission, which allows remote attackers to obtain sensitive information by sniffing the network during a PLC unlock request.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2022-34151 Use of hard-coded credentials vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine auto... (8.1 HIGH)
  • CVE-2022-33971 Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Ma... (7.5 HIGH)
  • CVE-2020-6986 In all versions of Omron PLC CJ Series, an attacker can send a series of specific data packets within a short period, causing a service e... (7.5 HIGH)
  • CVE-2019-18269 Omron’s CS and CJ series PLCs have an unrestricted externally accessible lock vulnerability (9.8 CRITICAL)
  • CVE-2019-13533 In Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monitor traffic between the PLC and the co... (8.1 HIGH)

Same CWE

  • CVE-2026-49219 ImageMagick is free and open-source software used for editing and manipulating digital images (5.5 MEDIUM)
  • CVE-2026-47165 ImageMagick is free and open-source software used for editing and manipulating digital images (4.1 MEDIUM)
  • CVE-2026-48855 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery
  • CVE-2026-45329 ESF-IDF is the Espressif Internet of Things (IOT) Development Framework (7.1 HIGH)
  • CVE-2026-9741 A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side Field Level Encryp... (6.5 MEDIUM)