PT-2023-26580 · Omron · Cj1W-Eip21+2

Published

2023-08-03

·

Updated

2024-10-17

·

CVE-2023-38744

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions CJ2M CPU Unit versions 2.18 and earlier CJ2H CPU Unit versions 3.04 and earlier CS/CJ Series EtherNet/IP Unit CS1W-EIP21 versions 3.04 and earlier CS/CJ Series EtherNet/IP Unit CJ1W-EIP21 versions 3.04 and earlier
Description A denial-of-service (DoS) issue exists due to improper validation of a specified type of input in the built-in EtherNet/IP port of the CJ Series CJ2 CPU unit and the communication function of the CS/CJ Series EtherNet/IP unit. If an affected product receives a specially crafted packet from a remote unauthenticated attacker, it may fall into a denial-of-service condition.
Recommendations For CJ2M CPU Unit versions 2.18 and earlier, update to a version later than 2.18 to resolve the issue. For CJ2H CPU Unit versions 3.04 and earlier, update to a version later than 3.04 to resolve the issue. For CS/CJ Series EtherNet/IP Unit CS1W-EIP21 versions 3.04 and earlier, update to a version later than 3.04 to resolve the issue. For CS/CJ Series EtherNet/IP Unit CJ1W-EIP21 versions 3.04 and earlier, update to a version later than 3.04 to resolve the issue. As a temporary workaround, consider restricting access to the EtherNet/IP port to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-38744

Affected Products

Cj1W-Eip21
Cj2H Cpu Unit
Cs1W-Eip21