CVE-2022-34151 is a hard-coded credentials vulnerability affecting various Omron Machine automation controllers (NJ, NX7, NX1 series), Sysmac Studio automation software, and NA series Programmable Terminals. A remote attacker could exploit this by analyzing the affected products to obtain these credentials, gaining full access to the controller. This vulnerability carries a high CVSS score of 8.1 due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While there is no public exploit code (Metasploit, Nuclei, ExploitDB) and it's not on CISA's KEV catalog, it has garnered significant community discussion and media coverage, including reports of exploitation by sophisticated ICS malware.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.28CPE matchmatch criteria | cpe:2.3:o:omron:nx701-1600_firmware:*:*:*:*:*:*:*:* | ||
<= 1.28CPE matchmatch criteria | cpe:2.3:o:omron:nx701-1700_firmware:*:*:*:*:*:*:*:* | ||
<= 1.28CPE matchmatch criteria | cpe:2.3:o:omron:nx701-z700_firmware:*:*:*:*:*:*:*:* | ||
<= 1.28CPE matchmatch criteria | cpe:2.3:o:omron:nx701-z600_firmware:*:*:*:*:*:*:*:* | ||
<= 1.28CPE matchmatch criteria | cpe:2.3:o:omron:nx701-1720_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.