Least Privilege Violation (CWE-272) Vulnerability exists in the communication function between the NJ/NX-series Machine Automation Controllers and the Sysmac Studio Software. An attacker may use this vulnerability to perform unauthorized access and to execute unauthorized code remotely to the controller products.
Metrics
Affected Vendors & Products
References
History
Mon, 14 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 14 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
Mon, 14 Jul 2025 00:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Least Privilege Violation (CWE-272) Vulnerability exists in the communication function between the NJ/NX-series Machine Automation Controllers and the Sysmac Studio Software. An attacker may use this vulnerability to perform unauthorized access and to execute unauthorized code remotely to the controller products. | |
Title | Least Privilege Violation Vulnerability in the communications functions of NJ/NX-series Machine Automation Controllers | |
Weaknesses | CWE-272 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: OMRON
Published: 2025-07-13T23:42:09.953Z
Updated: 2025-07-14T14:15:23.939Z
Reserved: 2025-02-16T23:57:46.232Z
Link: CVE-2025-1384

Updated: 2025-07-14T14:14:47.119Z

Status : Awaiting Analysis
Published: 2025-07-14T00:15:22.077
Modified: 2025-07-15T13:14:24.053
Link: CVE-2025-1384

No data.