CVE-2018-6624

OMRON NS devices 1.1 through 1.3 allow remote attackers to bypass authentication via a direct request to the .html file for a specific screen, as demonstrated by monitor.html.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:omron:ns_series_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:omron:ns10:-:*:*:*:*:*:*:*
cpe:2.3:h:omron:ns12:-:*:*:*:*:*:*:*
cpe:2.3:h:omron:ns15:-:*:*:*:*:*:*:*
cpe:2.3:h:omron:ns5:-:*:*:*:*:*:*:*
cpe:2.3:h:omron:ns8:-:*:*:*:*:*:*:*
cpe:2.3:h:omron:nsh5:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-02-05 18:29

Updated : 2023-12-10 12:30


NVD link : CVE-2018-6624

Mitre link : CVE-2018-6624

CVE.ORG link : CVE-2018-6624


JSON object : View

Products Affected

omron

  • nsh5
  • ns10
  • ns8
  • ns_series_firmware
  • ns15
  • ns12
  • ns5
CWE
CWE-425

Direct Request ('Forced Browsing')