Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2014-2407 | Cross-site scripting (XSS) vulnerability in the web application on Omron NS5, NS8, NS10, NS12, and NS15 HMI terminals 8.1xx through 8.68x allows remote authenticated users to inject arbitrary web script or HTML via crafted data. |
Solution
Omron Corporation has produced update, Version 8.69x for Japan and Version 8.7x for other countries, that mitigates the identified vulnerabilities. The updates for the NS series of HMI terminals can be downloaded at the following locations: NS15 Software Update Version 8.7: http://industrial.omron.us/en/products/catalogue/automation_systems/hmi/scalable_hmi/ns15/default.html NS12 Software Update Version 8.7: http://industrial.omron.us/en/products/catalogue/automation_systems/hmi/scalable_hmi/ns12/default.html NS10 Software Update Version 8.7: http://industrial.omron.us/en/products/catalogue/automation_systems/hmi/scalable_hmi/ns10/default.html NS8 Software Update Version 8.7: http://industrial.omron.us/en/products/catalogue/automation_systems/hmi/scalable_hmi/ns8/default.html NS5 Software Update Version 8.7: http://industrial.omron.us/en/products/catalogue/automation_systems/hmi/scalable_hmi/ns5/default.html
Workaround
No workaround given by the vendor.
Mon, 06 Oct 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | Omron NS Series HMI Improper Neutralization of Input During Web Page Generation | |
References |
| |
Metrics |
cvssV2_0
|
cvssV2_0
|

Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-10-06T18:01:21.608Z
Reserved: 2014-03-13T00:00:00
Link: CVE-2014-2370

No data.

Status : Deferred
Published: 2014-07-24T14:55:07.317
Modified: 2025-10-06T18:15:48.843
Link: CVE-2014-2370

No data.

No data.