PT-2023-21095 · Omron · Sysmac Cj-Series Cpu Units+4
Published
2023-04-17
·
Updated
2024-12-24
·
CVE-2023-27396
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SYSMAC CS-series CPU Units, all versions
SYSMAC CJ-series CPU Units, all versions
SYSMAC CP-series CPU Units, all versions
SYSMAC NJ-series CPU Units, all versions
SYSMAC NX1P-series CPU Units, all versions
SYSMAC NX102-series CPU Units, all versions
SYSMAC NX7 Database Connection CPU Units, version 1.16 and later
Description
FINS (Factory Interface Network Service) is a message communication protocol used in closed FA (Factory Automation) networks composed of OMRON products. The protocol has two security issues: (1) plaintext communication and (2) no authentication required. When FINS messages are intercepted, the contents may be retrieved. When arbitrary FINS messages are injected, any commands may be executed on, or the system information may be retrieved from, the affected device.
Recommendations
For SYSMAC CS-series CPU Units, consider implementing encryption and authentication mechanisms to secure FINS communication.
For SYSMAC CJ-series CPU Units, restrict access to the FINS protocol to minimize the risk of exploitation.
For SYSMAC CP-series CPU Units, disable any unnecessary FINS communication to reduce the attack surface.
For SYSMAC NJ-series CPU Units, implement secure authentication and authorization mechanisms for FINS messages.
For SYSMAC NX1P-series CPU Units, use secure communication protocols instead of plaintext FINS messages.
For SYSMAC NX102-series CPU Units, limit access to the FINS protocol to trusted devices and users.
For SYSMAC NX7 Database Connection CPU Units, version 1.16 and later, apply secure configuration settings to prevent unauthorized access to the FINS protocol.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sysmac Cj-Series Cpu Units
Sysmac Cp-Series Cpu Units
Sysmac Nx102-Series Cpu Units
Sysmac Nx1P-Series Cpu Units
Sysmac Nx7 Database Connection Cpu Units