PT-2022-3093 · Omron · Omron Sysmac Cx

Daniel Dos Santos

+1

·

Published

2022-06-22

·

Updated

2022-08-04

·

CVE-2022-31207

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18
Description The issue is related to a lack of cryptographic authentication in the Omron FINS (9600/TCP) protocol used for engineering purposes, including downloading projects and control logic to the PLC. This allows an attacker to manipulate transmitted object code to the PLC and execute arbitrary object code commands on the ASIC or the microprocessor interpreter. The logic downloaded to the PLC exists in compiled object code form and is executed after being passed to a dedicated ASIC or the microprocessor for interpretation.
Recommendations As a temporary workaround, consider restricting access to the FINS protocol to minimize the risk of exploitation. Avoid using the FINS Program Area Read and Program Area Write commands until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Verification of Data Authenticity

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03763
CVE-2022-31207

Affected Products

Omron Sysmac Cx