CVE-2024-27121
Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.88%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary file in the affected product may be accessed or arbitrary code may be executed by processing a specially crafted request sent from a remote attacker with an administrative privilege. As for the details of the affected product names/versions, see the information provided by the vendor under [References] section.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.88% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Source
- vultures@jpcert.or.jp
References
- https://jvn.jp/en/vu/JVNVU95852116/index.html
- https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2024-001_en.pdf
- https://www.fa.omron.co.jp/product/security/assets/pdf/ja/OMSR-2024-001_ja.pdf
- https://jvn.jp/en/vu/JVNVU95852116/index.html
- https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2024-001_en.pdf
- https://www.fa.omron.co.jp/product/security/assets/pdf/ja/OMSR-2024-001_ja.pdf
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.