CVE-2025-1384
Least Privilege Violation (CWE-272) Vulnerability exists in the communication function between the NJ/NX-series Machine Automation Controllers and the Sysmac Studio Software. An attacker may use this vulnerability to perform unauthorized access and to execute unauthorized code remotely to the controller products.
Scoring
- Severity
- HIGH
- CVSS base score
- 7
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
- EPSS probability
- 0.23%
- CWE
- CWE-272
- Published
- 2025-07-13
- Last modified
- 2026-03-13
Affected products
- OMRON Corporation Machine Automation Controller NJ-series
- OMRON Corporation Machine Automation Controller NJ-series
- OMRON Corporation Machine Automation Controller NJ-series
- OMRON Corporation Machine Automation Controller NJ-series
- OMRON Corporation Machine Automation Controller NJ-series
- OMRON Corporation Machine Automation Controller NJ-series
- OMRON Corporation Machine Automation Controller NJ-series
- OMRON Corporation Machine Automation Controller NJ-series
Weakness type
Related vulnerabilities
- CVE-2026-79693 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-79944 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2025-62299 — HCL IntelliOps Event Management is affected by multiple security vulnerabilities.
- CVE-2026-59915 — Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege...
- CVE-2026-49500 — Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain an Improper Link...
- CVE-2026-15271 — TOTOLINK EX200 Web boa.conf least privilege violation
- CVE-2026-15270 — D-link DIR-823G Web boa.conf least privilege violation
- CVE-2026-11620 — TOTOLINK EX200 vsftpd vsftpd.conf least privilege violation