Vulnerability Description
OMRON NS devices 1.1 through 1.3 allow remote attackers to bypass authentication via a direct request to the .html file for a specific screen, as demonstrated by monitor.html.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Omron | Ns Series Firmware | >= 1.1, <= 1.3 |
| Omron | Ns10 | - |
| Omron | Ns12 | - |
| Omron | Ns15 | - |
| Omron | Ns5 | - |
| Omron | Ns8 | - |
| Omron | Nsh5 | - |
Related Weaknesses (CWE)
References
- http://misteralfa-hack.blogspot.cl/2018/02/otomron-login-bypass.htmlThird Party Advisory
- http://misteralfa-hack.blogspot.cl/2018/02/otomron-login-bypass.htmlThird Party Advisory
FAQ
What is CVE-2018-6624?
CVE-2018-6624 is a vulnerability with a CVSS score of 9.8 (CRITICAL). OMRON NS devices 1.1 through 1.3 allow remote attackers to bypass authentication via a direct request to the .html file for a specific screen, as demonstrated by monitor.html.
How severe is CVE-2018-6624?
CVE-2018-6624 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-6624?
Check the references section above for vendor advisories and patch information. Affected products include: Omron Ns Series Firmware, Omron Ns10, Omron Ns12, Omron Ns15, Omron Ns5.