QSearchQSearch

CVE-2019-13533

8.1 HIGH

In Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monitor traffic between the PLC and the co...

Published: 2019-12-16 · Last updated: 2026-06-02

Severity and scoring

CVSS
8.1 HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H
CWE
CWE-294

Affected products

VendorProduct
omronplc_cj_firmware, plc_cs_firmware

Description

In Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monitor traffic between the PLC and the controller and replay requests that could result in the opening and closing of industrial valves.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2022-34151 Use of hard-coded credentials vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine auto... (8.1 HIGH)
  • CVE-2022-33971 Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Ma... (7.5 HIGH)
  • CVE-2020-6986 In all versions of Omron PLC CJ Series, an attacker can send a series of specific data packets within a short period, causing a service e... (7.5 HIGH)
  • CVE-2019-18269 Omron’s CS and CJ series PLCs have an unrestricted externally accessible lock vulnerability (9.8 CRITICAL)
  • CVE-2015-0987 Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmissi... (10.0 CRITICAL)

Same CWE

  • CVE-2026-49322 Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-... (4.3 MEDIUM)
  • CVE-2026-9095 Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection (8.1 HIGH)
  • CVE-2026-46538 Microsoft UFO open-source framework for intelligent automation across devices and platforms (5.9 MEDIUM)
  • CVE-2026-9398 A security vulnerability has been detected in Besen BS20 EV Charging Station up to 20260426 (3.1 LOW)
  • CVE-2026-37982 A flaw was found in Keycloak (6.8 MEDIUM)