Back to overview

CVE-2015-0987

CRITICAL
10.0
CVSS 3.1
Description
Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission, which allows remote attackers to obtain sensitive information by sniffing the network during a PLC unlock request.

Metadata

CVE ID
CVE-2015-0987
State
PUBLISHED
Assigner
icscert
Reserved
2015-01-10 00:00 UTC
Published
2015-10-03 10:00 UTC
Last updated
2026-06-02 19:48 UTC
Primary CWE
CWE-319
CWE-319 Cleartext Transmission of Sensitive Information
Vendor / Product
n/a / n/a
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
n/a n/a n/a
Weakness (CWE)
CWESourceDescription
cna n/a
CWE-319 adp CWE-319 Cleartext Transmission of Sensitive Information
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:H
Back to overview