CVE-2023-38744
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Denial-of-service (DoS) vulnerability due to improper validation of specified type of input issue exists in the built-in EtherNet/IP port of the CJ Series CJ2 CPU unit and the communication function of the CS/CJ Series EtherNet/IP unit. If an affected product receives a packet which is specially crafted by a remote unauthenticated attacker, the unit of the affected product may fall into a denial-of-service (DoS) condition. Affected products/versions are as follows: CJ2M CPU Unit CJ2M-CPU3[] Unit version of the built-in EtherNet/IP section Ver. 2.18 and earlier, CJ2H CPU Unit CJ2H-CPU6[]-EIP Unit version of the built-in EtherNet/IP section Ver. 3.04 and earlier, CS/CJ Series EtherNet/IP Unit CS1W-EIP21 V3.04 and earlier, and CS/CJ Series EtherNet/IP Unit CJ1W-EIP21 V3.04 and earlier.
Affected (12)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.18 |
| Running on/with | Platform Versions |
|---|---|
Omron Cj2m Cpu35 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.18 |
| Running on/with | Platform Versions |
|---|---|
Omron Cj2m Cpu34 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.18 |
| Running on/with | Platform Versions |
|---|---|
Omron Cj2m Cpu33 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.18 |
| Running on/with | Platform Versions |
|---|---|
Omron Cj2m Cpu32 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.18 |
| Running on/with | Platform Versions |
|---|---|
Omron Cj2m Cpu31 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.04 |
| Running on/with | Platform Versions |
|---|---|
Omron Cj2h Cpu68 Eip | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.04 |
| Running on/with | Platform Versions |
|---|---|
Omron Cj2h Cpu67 Eip | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.04 |
| Running on/with | Platform Versions |
|---|---|
Omron Cj2h Cpu66 Eip | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.04 |
| Running on/with | Platform Versions |
|---|---|
Omron Cj2h Cpu65 Eip | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.04 |
| Running on/with | Platform Versions |
|---|---|
Omron Cj2h Cpu64 Eip | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.04 |
| Running on/with | Platform Versions |
|---|---|
Omron Cs1w Eip21 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.04 |
| Running on/with | Platform Versions |
|---|---|
Omron Cj1w Eip21 | All versions |
References (4)
Source: vultures@jpcert.or.jp
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.