CVE-2025-1384: Least Privilege Violation Vulnerability in the communications functions of NJ/NX-series Machine Automation Controllers
Least Privilege Violation (CWE-272) Vulnerability exists in the communication function between the NJ/NX-series Machine Automation Controllers and the Sysmac Studio Software. An attacker may use this vulnerability to perform unauthorized access and to execute unauthorized code remotely to the controller products.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1384?
CVE-2025-1384 is classified as a least privilege violation vulnerability.
How do I fix CVE-2025-1384?
To mitigate CVE-2025-1384, update your Omron NJ/NX-series Machine Automation Controllers and Sysmac Studio Software to the latest version.
What products are affected by CVE-2025-1384?
CVE-2025-1384 affects Omron NJ/NX-series Machine Automation Controllers and Omron Sysmac Studio Software.
What can an attacker do with CVE-2025-1384?
An attacker can exploit CVE-2025-1384 to gain unauthorized access and execute unauthorized code remotely.
Is CVE-2025-1384 being actively exploited?
There is no public evidence indicating that CVE-2025-1384 is being actively exploited in the wild, but mitigation is strongly advised.