SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-31205

In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in memory area D1449...D1452 and can be read out using the Omron FINS protocol without any further authentication.

HIGH 7.5EPSS 0.63%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.63%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in memory area D1449...D1452 and can be read out using the Omron FINS protocol without any further authentication.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
0.63% probability · 48th percentile
CISA KEV
Not listed
Weakness
CWE-312
Affected
omron/sysmac cs1 firmware · omron/sysmac cj2m firmware · omron/sysmac cj2h firmware · omron/sysmac cp1e firmware · omron/sysmac cp1h firmware · omron/sysmac cp1l firmware · omron/cp1w-cif41 firmware
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.