QSearchQSearch

CVE-2022-33971

7.5 HIGH

Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Ma...

Published: 2022-07-04 · Last updated: 2026-06-02

Severity and scoring

CVSS
7.5 HIGH
Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-294, CWE-489

Affected products

VendorProduct
omronnj-pa3001_firmware, nj-pd3001_firmware, nj101-1000_firmware

Description

Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, and Machine automation controller NJ series all models V 1.48 and earlier, which may allow an adjacent attacker who can analyze the communication between the controller and the specific software used by OMRON internally to cause a denial-of-service (DoS) condition or execute a malicious program.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2022-34151 Use of hard-coded credentials vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine auto... (8.1 HIGH)
  • CVE-2020-6986 In all versions of Omron PLC CJ Series, an attacker can send a series of specific data packets within a short period, causing a service e... (7.5 HIGH)
  • CVE-2019-18269 Omron’s CS and CJ series PLCs have an unrestricted externally accessible lock vulnerability (9.8 CRITICAL)
  • CVE-2019-13533 In Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monitor traffic between the PLC and the co... (8.1 HIGH)
  • CVE-2015-0987 Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmissi... (10.0 CRITICAL)

Same CWE

  • CVE-2026-49188 The ai_cmd utility executes with full root permissions (9.8 CRITICAL)
  • CVE-2026-49322 Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-... (4.3 MEDIUM)
  • CVE-2026-9095 Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection (8.1 HIGH)
  • CVE-2026-46538 Microsoft UFO open-source framework for intelligent automation across devices and platforms (5.9 MEDIUM)
  • CVE-2026-45728 Algernon is a small self-contained pure-Go web server (7.5 HIGH)