CVE-2019-13533
8.1 HIGHIn Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monitor traffic between the PLC and the co...
Published: 2019-12-16 · Last updated: 2026-06-02
Severity and scoring
- CVSS
- 8.1 HIGH
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H
- CWE
- CWE-294
Affected products
| Vendor | Product |
|---|---|
| omron | plc_cj_firmware, plc_cs_firmware |
Description
In Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monitor traffic between the PLC and the controller and replay requests that could result in the opening and closing of industrial valves.
Source: NVD
References
Related CVEs
Same vendor
- CVE-2022-34151 — Use of hard-coded credentials vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine auto... (8.1 HIGH)
- CVE-2022-33971 — Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Ma... (7.5 HIGH)
- CVE-2020-6986 — In all versions of Omron PLC CJ Series, an attacker can send a series of specific data packets within a short period, causing a service e... (7.5 HIGH)
- CVE-2019-18269 — Omron’s CS and CJ series PLCs have an unrestricted externally accessible lock vulnerability (9.8 CRITICAL)
- CVE-2015-0987 — Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmissi... (10.0 CRITICAL)
Same CWE
- CVE-2026-49322 — Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-... (4.3 MEDIUM)
- CVE-2026-9095 — Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection (8.1 HIGH)
- CVE-2026-46538 — Microsoft UFO open-source framework for intelligent automation across devices and platforms (5.9 MEDIUM)
- CVE-2026-9398 — A security vulnerability has been detected in Besen BS20 EV Charging Station up to 20260426 (3.1 LOW)
- CVE-2026-37982 — A flaw was found in Keycloak (6.8 MEDIUM)