CVE-2022-31205
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in memory area D1449...D1452 and can be read out using the Omron FINS protocol without any further authentication.
Affected (7)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1 |
| Running on/with | Platform Versions |
|---|---|
Omron Sysmac Cs1 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.1 |
| Running on/with | Platform Versions |
|---|---|
Omron Sysmac Cj2m | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.5 |
| Running on/with | Platform Versions |
|---|---|
Omron Sysmac Cj2h | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.30 |
| Running on/with | Platform Versions |
|---|---|
Omron Sysmac Cp1e | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.30 |
| Running on/with | Platform Versions |
|---|---|
Omron Sysmac Cp1h | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.10 |
| Running on/with | Platform Versions |
|---|---|
Omron Sysmac Cp1l | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Omron Cp1w Cif41 | All versions |
References (4)
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.