CVE-2022-33208: High severity omron nx701-1600 vulnerability
Authentication bypass by capture-replay vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, Automation software 'Sysmac Studio' all models V1.49 and earlier, and Programmable Terminal (PT) NA series NA5-15W/NA5-12W/NA5-9W/NA5-7W models Runtime V1.15 and earlier, which may allow a remote attacker who can analyze the communication between the affected controller and automation software 'Sysmac Studio' and/or a Programmable Terminal (PT) to access the controller.
Affected Software
Event History
Frequently Asked Questions
What systems are affected by CVE-2022-33208?
CVE-2022-33208 affects various Omron Machine automation controllers including NJ series, NX7 series, NX1 series, and several firmware versions up to 1.48 and 1.28.
What is the nature of the vulnerability in CVE-2022-33208?
CVE-2022-33208 is an authentication bypass vulnerability that allows capture-replay attacks.
How can CVE-2022-33208 be mitigated or fixed?
To fix CVE-2022-33208, you should upgrade impacted devices to the latest firmware versions that address this vulnerability.
What is the risk associated with CVE-2022-33208?
The risk associated with CVE-2022-33208 includes unauthorized access to affected systems, which can lead to potential misuse of automation tasks.
Is there a security advisory available for CVE-2022-33208?
Yes, a security advisory regarding CVE-2022-33208 is available from Omron detailing the affected products and recommended actions.