CVE-2015-0987: Omron CJ2H PLC

Critical severity, CVSS 10.0. EPSS: 1.2% chance of exploitation in the next 30 days.

Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission, which allows remote attackers to obtain sensitive information by sniffing the network during a PLC unlock request.

Affected products

  • Omron CJ2H PLC: up to and including 1.4
  • Omron CJ2M PLC: up to and including 2.0
  • Omron Cx-Programmer: up to and including 9.5

Published 2015-10-06. Last modified 2026-06-17.