CVE-2025-1384 Information

Description

Least Privilege Violation (CWE-272) Vulnerability exists in the communication function between the NJ/NX-series Machine Automation Controllers and the Sysmac Studio Software. An attacker may use this vulnerability to perform unauthorized access and to execute unauthorized code remotely to the controller products.

Reference

https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2025-004_en.pdf https://www.fa.omron.co.jp/product/security/assets/pdf/ja/OMSR-2025-004_ja.pdf

CNNVD-202507-1794 (Published: 2025-07-13)

Share on: