CVE-2025-1384 – Omron NJ/NX-series Least Privilege Violation Remote Code Execution

The following table lists the changes that have been made to the
CVE-2025-1384 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by bba440f9-ef23-4224-aa62-7ac0935d18d1

    Jul. 14, 2025

    Action Type Old Value New Value
    Added Description Least Privilege Violation (CWE-272) Vulnerability exists in the communication function between the NJ/NX-series Machine Automation Controllers and the Sysmac Studio Software. An attacker may use this vulnerability to perform unauthorized access and to execute unauthorized code remotely to the controller products.
    Added CVSS V3.1 AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
    Added CWE CWE-272
    Added Reference https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2025-004_en.pdf
    Added Reference https://www.fa.omron.co.jp/product/security/assets/pdf/ja/OMSR-2025-004_ja.pdf
Share the Post:

Related Posts