Cyber Resilience

CVE-2022-33971

HighUpdated

Published: 04 July 2022

Published
04 July 2022
Modified
02 June 2026
KEV Added
Patch
CVSS Score v3.1 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0075 73.6th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2022-33971 is a high-severity Authentication Bypass by Capture-replay (CWE-294) vulnerability in Omron Nx701-1600 Firmware. Its CVSS base score is 7.5 (High).

Operationally, ranked in the top 26.4% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability details

Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, and Machine automation controller NJ series all models V 1.48 and earlier, which…

more

may allow an adjacent attacker who can analyze the communication between the controller and the specific software used by OMRON internally to cause a denial-of-service (DoS) condition or execute a malicious program.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

omron
nx701-1600 firmware
≤ 1.28
omron
nx701-1700 firmware
≤ 1.28
omron
nx701-z700 firmware
≤ 1.28
omron
nx701-z600 firmware
≤ 1.28
omron
nx701-1720 firmware
≤ 1.28
omron
nx701-1620 firmware
≤ 1.28
omron
nx102-1200 firmware
≤ 1.48
omron
nx102-1100 firmware
≤ 1.48
omron
nx102-1000 firmware
≤ 1.48
omron
nx102-1220 firmware
≤ 1.48
+42 more product configuration(s) — see NVD for full list

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-294

Allows detection of capture-replay attacks by showing the replayed logon's timestamp as the last logon.

addresses: CWE-294

Protects against replay of captured session tokens or credentials by requiring authenticated, fresh session channels.

addresses: CWE-489

Minimal functionality precludes inclusion of active debug code or diagnostic interfaces.

addresses: CWE-294

Wireless link protections commonly incorporate replay protection, reducing the exploitability of capture-replay weaknesses.

addresses: CWE-294

Accurate synchronized time enables tight timestamp windows that directly limit capture-replay windows in authentication protocols.

References