Back to Database
Status published
Medium
CVE-2024-12298
Vulnerability Report on Improper Restriction of XML External Entity Reference in NB-Designer
Vulnerability Description
We found a vulnerability Improper Restriction of XML External Entity Reference (CWE-611) in NB-series NX-Designer. Attackers may be able to abuse this vulnerability to disclose confidential data on a computer.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-12298
Credits & Attribution
No credits recorded in the NVD database.
References
More from OMRON Corporation
View All →CVE-2025-1384
Least Privilege Violation Vulnerability in the communications functions of NJ/NX-series Machine Automation Controllers
High
7
CVE-2025-0591
Out-of-bounds Read vulnerability in CX-Programmer
High
7.8
CVE-2024-49501
Sysmac Studio provided by OMRON Corporation contains an incorrect authorization...
Medium
5.7
CVE-2024-33687
Insufficient verification of data authenticity issue exists in NJ Series...
Unknown
0
CVE-2024-31413
Free of pointer not at start of buffer vulnerability exists...
Unknown
0
Affected Vendor
OMRON Corporation
View all reports →Affected Software
Programable Terminals NB-Designer
Vulnerable Versions:
Ver.1.63 or lower
Timeline
Official Publish:
January 14th, 2025
Last Modified:
January 14th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N