CVE-2022-31204
They feature a UM Protection setting that allows users or system integrators to configure a password in order to restrict sensitive engineering operations (such as project/logic uploads and downloads).
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.62%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Omron CS series, CJ series, and CP series PLCs through 2022-05-18 use cleartext passwords. They feature a UM Protection setting that allows users or system integrators to configure a password in order to restrict sensitive engineering operations (such as project/logic uploads and downloads). This password is set using the OMRON FINS command Program Area Protect and unset using the command Program Area Protect Clear, both of which are transmitted in cleartext.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.62% probability · 48th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-319
- Affected
- omron/sysmac cs1 firmware · omron/sysmac cj2m firmware · omron/sysmac cj2h firmware · omron/sysmac cp1e firmware · omron/sysmac cp1h firmware · omron/sysmac cp1l firmware · omron/cp1w-cif41 firmware · omron/cx-programmer
- Source
- cve@mitre.org
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-179-02Third Party Advisory, US Government Resource
- https://www.forescout.com/blog/Third Party Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-179-02Third Party Advisory, US Government Resource
- https://www.forescout.com/blog/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.