PT-2022-6229 · Omron · Omron Cp1L-El20Dr-D

Georgy Kiguradze

·

Published

2022-12-27

·

Updated

2025-04-04

·

CVE-2023-22357

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OMRON CP1L-EL20DR-D all versions
Description The issue is related to the implementation of the Factory Interface Network Service (FINS) protocol in the OMRON CP1L-EL20DR-D programmable logic controller's firmware, specifically due to insufficient protection of service data in the debug code implementation. This could allow a remote attacker to read, modify, or delete files, execute arbitrary code, or cause a denial-of-service condition. The presence of active debug code may lead to the execution of unspecified FINS protocol commands without authentication, enabling a remote unauthenticated attacker to read/write in arbitrary areas of the device memory. This could result in overwriting the firmware, causing a denial-of-service condition, and/or arbitrary code execution.
Recommendations As a temporary workaround, consider disabling the debug code functionality until a patch is available. Restrict access to the device to minimize the risk of exploitation. Avoid using the device until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Improper Resource Release

Weakness Enumeration

Related Identifiers

BDU:2023-00542
CVE-2023-22357

Affected Products

Omron Cp1L-El20Dr-D