Back

MEDIUM

Omron NS Series HMI Cross-Site Request Forgery

Published Jul 24, 2014

Description

Cross-site request forgery (CSRF) vulnerability in the web application on Omron NS5, NS8, NS10, NS12, and NS15 HMI terminals 8.1xx through 8.68x allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

Affected products

Remediation

Vendor solution

Omron Corporation has produced update, Version 8.69x for Japan and Version 8.7x for other countries, that mitigates the identified vulnerabilities. The updates for the NS series of HMI terminals can be downloaded at the following locations:

NS15 Software Update Version 8.7:

http://industrial.omron.us/en/products/catalogue/automation_systems/hmi/scalable_hmi/ns15/default.html

NS12 Software Update Version 8.7:

http://industrial.omron.us/en/products/catalogue/automation_systems/hmi/scalable_hmi/ns12/default.html

NS10 Software Update Version 8.7:

http://industrial.omron.us/en/products/catalogue/automation_systems/hmi/scalable_hmi/ns10/default.html

NS8 Software Update Version 8.7:

http://industrial.omron.us/en/products/catalogue/automation_systems/hmi/scalable_hmi/ns8/default.html

NS5 Software Update Version 8.7:

http://industrial.omron.us/en/products/catalogue/automation_systems/hmi/scalable_hmi/ns5/default.html

Metrics

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Jul 24, 2014
Updated Oct 6, 2025
Reserved Mar 13, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a