Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, and Machine automation controller NJ series all models V 1.48 and earlier, which may allow an adjacent attacker who can analyze the communication between the controller and the specific software used by OMRON internally to cause a denial-of-service (DoS) condition or execute a malicious program.
History

Wed, 03 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-489
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2022-07-04T01:50:54.000Z

Updated: 2026-06-02T19:44:14.367Z

Reserved: 2022-06-21T00:00:00.000Z

Link: CVE-2022-33971

cve-icon Vulnrichment

Updated: 2024-08-03T08:16:16.110Z

cve-icon NVD

Status : Modified

Published: 2022-07-04T02:15:07.670

Modified: 2026-06-02T21:16:25.360

Link: CVE-2022-33971

cve-icon Redhat

No data.