Vulnerability Description
Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 use a reversible format for password storage in object files on Compact Flash cards, which makes it easier for local users to obtain sensitive information by reading a file.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Omron | Cx-Programmer | 9.5 |
| Omron | Cj2H Plc | 1.4 |
| Omron | Cj2M Plc | 2.0 |
Related Weaknesses (CWE)
References
- https://ics-cert.us-cert.gov/advisories/ICSA-15-274-01Third Party AdvisoryUS Government Resource
- https://ics-cert.us-cert.gov/advisories/ICSA-15-274-01Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2015-1015?
CVE-2015-1015 is a vulnerability with a CVSS score of 2.1 (LOW). Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 use a reversible format for password storage in object files on Compact Flash cards, which makes it ...
How severe is CVE-2015-1015?
CVE-2015-1015 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-1015?
Check the references section above for vendor advisories and patch information. Affected products include: Omron Cx-Programmer, Omron Cj2H Plc, Omron Cj2M Plc.