Insufficient verification of data authenticity in NJ-series Machine Automation Controller and NX-series Machine Automation Controller - CVE-2024-33687

 

Insufficient verification of data authenticity in NJ-series Machine Automation Controller and NX-series Machine Automation Controller - CVE-2024-33687

Published: May 28, 2024


Vulnerability identifier: #VU89853
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2024-33687
CWE-ID: CWE-345
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
NJ-series Machine Automation Controller
NX-series Machine Automation Controller
Software vendor:
Omron

Description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to insufficient verification of data authenticity. A remote attacker can alter a user program, leading to the affected product may not be able to detect the alteration.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links