Use of hard-coded credentials in Omron products - CVE-2022-34151
Published: July 4, 2022 / Updated: November 11, 2022
Vulnerability details
The vulnerability allows a remote attacker to gain full access to vulnerable system.
The vulnerability exists due to presence of hard-coded credentials in application code. A remote unauthenticated attacker can access the affected system using the hard-coded credentials.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
NX1-series Machine Automation Controller
NJ-series Machine Automation Controller
Automation Software Sysmac Studio
NA-series Programable Terminal NA5-15W
NA-series Programable Terminal NA5-12W
NA-series Programable Terminal NA5-9W
NA-series Programable Terminal NA5-7W
How to mitigate CVE-2022-34151
NX1-series Machine Automation Controller - update to 1.49
NJ-series Machine Automation Controller - update to 1.49
Automation Software Sysmac Studio - update to 1.50
NA-series Programable Terminal NA5-15W - update to 1.16
NA-series Programable Terminal NA5-12W - update to 1.16
NA-series Programable Terminal NA5-9W - update to 1.16
NA-series Programable Terminal NA5-7W - update to 1.16