CVE-2015-0987
Last modified
CVE-2015-0987 is a critical-severity vulnerability rated 10/10 on the CVSS scale. Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission, which allows remote attackers to obtain sensitive information by sniffing the network during a PLC unlock request.. EPSS estimates a 1.16% chance of exploitation in the next 30 days.
Description
Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission, which allows remote attackers to obtain sensitive information by sniffing the network during a PLC unlock request.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Omron | Cx-Programmer | <= 9.5 |
| Omron | Cj2h Plc | <= 1.4 |
| Omron | Cj2m Plc | <= 2.0 |
References
- https://ics-cert.us-cert.gov/advisories/ICSA-15-274-01Third Party Advisory, US Government Resource
- https://ics-cert.us-cert.gov/advisories/ICSA-15-274-01Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-0987?
How severe is CVE-2015-0987?
How do I fix CVE-2015-0987?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-0981The SOAP web interface in SCADA Engine BACnet OPC Server bef…
- CVE-2015-0982Buffer overflow in an unspecified DLL in Schneider Electric …
- CVE-2015-0983Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2015-0984Directory traversal vulnerability in the FTP server on Honey…
- CVE-2015-0985Cross-site request forgery (CSRF) vulnerability in XZERES 44…
- CVE-2015-0986Multiple stack-based buffer overflows in Moxa VPort ActiveX …
- CVE-2015-0988Omron CX-One CX-Programmer before 9.6 uses a reversible form…
- CVE-2015-0989PACTware 4.1 SP3 allows remote attackers to cause a denial o…
- CVE-2015-0990Untrusted search path vulnerability in Ecava IntegraXor SCAD…
- CVE-2015-0991Inductive Automation Ignition 7.7.2 allows remote attackers …
- CVE-2015-0992Inductive Automation Ignition 7.7.2 stores cleartext OPC Ser…
- CVE-2015-0993Inductive Automation Ignition 7.7.2 does not terminate a ses…
Are you affected by CVE-2015-0987?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
