# CVE-2025-1384

## Summary

- **CVE ID:** CVE-2025-1384
- **Severity:** HIGH
- **CVSS Score:** 7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H)
- **CWE:** CWE-272
- **Published:** Jul 13, 2025
- **Last Modified:** Mar 13, 2026

## Description

Least Privilege Violation (CWE-272) Vulnerability exists in the communication function between the NJ/NX-series Machine Automation Controllers and the Sysmac Studio Software. An attacker may use this vulnerability to perform unauthorized access and to execute unauthorized code remotely to the controller products.

## Affected Products

- OMRON Corporation — Machine Automation Controller NJ-series (NJ101-[][][][] Ver.1.67.00 or lower)
- OMRON Corporation — Machine Automation Controller NJ-series (NJ301-1[]00 Ver.1.67.00 or lower)
- OMRON Corporation — Machine Automation Controller NJ-series (NJ501-1[]00 Ver.1.67.02 or lower)
- OMRON Corporation — Machine Automation Controller NJ-series (NJ501-1[]20 Ver.1.68.01 or lower)
- OMRON Corporation — Machine Automation Controller NJ-series (NJ501-1340 Ver.1.67.00 or lower)
- OMRON Corporation — Machine Automation Controller NJ-series (NJ501-4[][][] Ver.1.67.00 or lower)
- OMRON Corporation — Machine Automation Controller NJ-series (NJ501-5300 Ver.1.67.01 or lower)
- OMRON Corporation — Machine Automation Controller NJ-series (NJ501-R[]00 Ver.1.67.01 or lower)
- OMRON Corporation — Machine Automation Controller NJ-series (NJ501-R[]20 Ver.1.67.00 or lower)
- OMRON Corporation — Machine Automation Controller NX-series (NX102-[][][][] Ver.1.68.01 or lower)
- OMRON Corporation — Machine Automation Controller NX-series (NX1P2-[][][][][][] Ver.1.64.09 or lower)
- OMRON Corporation — Machine Automation Controller NX-series (NX1P2-[][][][][][]1 Ver.1.64.09 or lower)
- OMRON Corporation — Machine Automation Controller NX-series (NX502-[][][][] Ver.1.68.01 or lower)
- OMRON Corporation — Machine Automation Controller NX-series (NX701-[][][][] Ver.1.35.09 or lower)
- OMRON Corporation — Sysmac Studio Software (SYSMAC-SE2[][][] all)

## References

- [CNA](https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2025-004_en.pdf)
- [CNA](https://www.fa.omron.co.jp/product/security/assets/pdf/ja/OMSR-2025-004_ja.pdf)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.23%
- **EPSS Percentile:** 14.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._