PT-2022-3096 · Omron · Omron Cs Series
Daniel Dos Santos
+1
·
Published
2022-06-22
·
Updated
2022-08-04
·
CVE-2022-31204
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Omron CS series, CJ series, and CP series PLCs through 2022-05-18
Description
The issue concerns the transmission of confidential information in cleartext, specifically passwords used for the UM Protection setting. This setting allows users or system integrators to configure a password to restrict sensitive engineering operations, such as project/logic uploads and downloads. The passwords are set using the OMRON FINS command
Program Area Protect and unset using the command Program Area Protect Clear, both of which are transmitted in cleartext. This could allow a remote attacker to gain unauthorized access to protected information.Recommendations
For Omron CS series, CJ series, and CP series PLCs through 2022-05-18, consider disabling the UM Protection setting until a secure method of password transmission is implemented. Restrict access to the
Program Area Protect and Program Area Protect Clear commands to minimize the risk of exploitation. Avoid using cleartext passwords for sensitive engineering operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Omron Cs Series