PT-2023-21095 · Omron · Sysmac Cj-Series Cpu Units+4

Published

2023-04-17

·

Updated

2024-12-24

·

CVE-2023-27396

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SYSMAC CS-series CPU Units, all versions SYSMAC CJ-series CPU Units, all versions SYSMAC CP-series CPU Units, all versions SYSMAC NJ-series CPU Units, all versions SYSMAC NX1P-series CPU Units, all versions SYSMAC NX102-series CPU Units, all versions SYSMAC NX7 Database Connection CPU Units, version 1.16 and later
Description FINS (Factory Interface Network Service) is a message communication protocol used in closed FA (Factory Automation) networks composed of OMRON products. The protocol has two security issues: (1) plaintext communication and (2) no authentication required. When FINS messages are intercepted, the contents may be retrieved. When arbitrary FINS messages are injected, any commands may be executed on, or the system information may be retrieved from, the affected device.
Recommendations For SYSMAC CS-series CPU Units, consider implementing encryption and authentication mechanisms to secure FINS communication. For SYSMAC CJ-series CPU Units, restrict access to the FINS protocol to minimize the risk of exploitation. For SYSMAC CP-series CPU Units, disable any unnecessary FINS communication to reduce the attack surface. For SYSMAC NJ-series CPU Units, implement secure authentication and authorization mechanisms for FINS messages. For SYSMAC NX1P-series CPU Units, use secure communication protocols instead of plaintext FINS messages. For SYSMAC NX102-series CPU Units, limit access to the FINS protocol to trusted devices and users. For SYSMAC NX7 Database Connection CPU Units, version 1.16 and later, apply secure configuration settings to prevent unauthorized access to the FINS protocol.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2025-01902
CVE-2023-27396

Affected Products

Sysmac Cj-Series Cpu Units
Sysmac Cp-Series Cpu Units
Sysmac Nx102-Series Cpu Units
Sysmac Nx1P-Series Cpu Units
Sysmac Nx7 Database Connection Cpu Units