Authentication bypass by capture-replay vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, Automation software 'Sysmac Studio' all models V1.49 and earlier, and Programmable Terminal (PT) NA series NA5-15W/NA5-12W/NA5-9W/NA5-7W models Runtime V1.15 and earlier, which may allow a remote attacker who can analyze the communication between the affected controller and automation software 'Sysmac Studio' and/or a Programmable Terminal (PT) to access the controller.

Project Subscriptions

Vendors Products
Na5-12w Subscribe
Na5-12w Firmware Subscribe
Na5-15w Subscribe
Na5-15w Firmware Subscribe
Na5-7w Firmware Subscribe
Na5-9w Firmware Subscribe
Nj-pa3001 Subscribe
Nj-pa3001 Firmware Subscribe
Nj-pd3001 Subscribe
Nj-pd3001 Firmware Subscribe
Nj101-1000 Subscribe
Nj101-1000 Firmware Subscribe
Nj101-1020 Subscribe
Nj101-1020 Firmware Subscribe
Nj101-9000 Subscribe
Nj101-9000 Firmware Subscribe
Nj101-9020 Subscribe
Nj101-9020 Firmware Subscribe
Nj301-1100 Subscribe
Nj301-1100 Firmware Subscribe
Nj301-1200 Subscribe
Nj301-1200 Firmware Subscribe
Nj501-1300 Subscribe
Nj501-1300 Firmware Subscribe
Nj501-1320 Subscribe
Nj501-1320 Firmware Subscribe
Nj501-1340 Subscribe
Nj501-1340 Firmware Subscribe
Nj501-140 Subscribe
Nj501-140 Firmware Subscribe
Nj501-1420 Subscribe
Nj501-1420 Firmware Subscribe
Nj501-1500 Subscribe
Nj501-1500 Firmware Subscribe
Nj501-1520 Subscribe
Nj501-1520 Firmware Subscribe
Nj501-4300 Subscribe
Nj501-4300 Firmware Subscribe
Nj501-4310 Subscribe
Nj501-4310 Firmware Subscribe
Nj501-4320 Subscribe
Nj501-4320 Firmware Subscribe
Nj501-4400 Subscribe
Nj501-4400 Firmware Subscribe
Nj501-4500 Subscribe
Nj501-4500 Firmware Subscribe
Nj501-5300 Subscribe
Nj501-5300 Firmware Subscribe
Nj501-r300 Subscribe
Nj501-r300 Firmware Subscribe
Nj501-r320 Subscribe
Nj501-r320 Firmware Subscribe
Nj501-r400 Subscribe
Nj501-r400 Firmware Subscribe
Nj501-r420 Subscribe
Nj501-r420 Firmware Subscribe
Nj501-r500 Subscribe
Nj501-r500 Firmware Subscribe
Nj501-r520 Subscribe
Nj501-r520 Firmware Subscribe
Nx102-1000 Subscribe
Nx102-1000 Firmware Subscribe
Nx102-1020 Subscribe
Nx102-1020 Firmware Subscribe
Nx102-1100 Subscribe
Nx102-1100 Firmware Subscribe
Nx102-1120 Subscribe
Nx102-1120 Firmware Subscribe
Nx102-1200 Subscribe
Nx102-1200 Firmware Subscribe
Nx102-1220 Subscribe
Nx102-1220 Firmware Subscribe
Nx102-9020 Subscribe
Nx102-9020 Firmware Subscribe
Nx1p2-1040dt Subscribe
Nx1p2-1040dt1 Subscribe
Nx1p2-1040dt1 Firmware Subscribe
Nx1p2-1040dt Firmware Subscribe
Nx1p2-1140dt Subscribe
Nx1p2-1140dt1 Subscribe
Nx1p2-1140dt1 Firmware Subscribe
Nx1p2-1140dt Firmware Subscribe
Nx1p2-9024dt Subscribe
Nx1p2-9024dt1 Subscribe
Nx1p2-9024dt1 Firmware Subscribe
Nx1p2-9024dt Firmware Subscribe
Nx1w-adb21 Subscribe
Nx1w-adb21 Firmware Subscribe
Nx1w-cif01 Subscribe
Nx1w-cif01 Firmware Subscribe
Nx1w-cif11 Subscribe
Nx1w-cif11 Firmware Subscribe
Nx1w-cif12 Subscribe
Nx1w-cif12 Firmware Subscribe
Nx1w-dab21v Subscribe
Nx1w-dab21v Firmware Subscribe
Nx1w-mab221 Subscribe
Nx1w-mab221 Firmware Subscribe
Nx701-1600 Subscribe
Nx701-1600 Firmware Subscribe
Nx701-1620 Subscribe
Nx701-1620 Firmware Subscribe
Nx701-1700 Subscribe
Nx701-1700 Firmware Subscribe
Nx701-1720 Subscribe
Nx701-1720 Firmware Subscribe
Nx701-z600 Subscribe
Nx701-z600 Firmware Subscribe
Nx701-z700 Subscribe
Nx701-z700 Firmware Subscribe
Sysmac Studio Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-36251 Authentication bypass by capture-replay vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, Automation software 'Sysmac Studio' all models V1.49 and earlier, and Programmable Terminal (PT) NA series NA5-15W/NA5-12W/NA5-9W/NA5-7W models Runtime V1.15 and earlier, which may allow a remote attacker who can analyze the communication between the affected controller and automation software 'Sysmac Studio' and/or a Programmable Terminal (PT) to access the controller.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2024-08-03T08:01:20.422Z

Reserved: 2022-06-21T00:00:00

Link: CVE-2022-33208

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-07-04T02:15:07.570

Modified: 2024-11-21T07:07:43.217

Link: CVE-2022-33208

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses