VulnerabilityModified
CVE-2022-45790
Authentication is susceptible to bruteforce attack, which may allow an adversary to gain access to protected memory.
CRITICAL 9.1EPSS 0.70%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.70%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Omron FINS protocol has an authenticated feature to prevent access to memory regions. Authentication is susceptible to bruteforce attack, which may allow an adversary to gain access to protected memory. This access can allow overwrite of values including programmed logic.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 0.70% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-307
- Affected
- omron/cj1g-cpu45p firmware · omron/cj1g-cpu45p-gtc firmware · omron/cj1g-cpu44p firmware · omron/cj1g-cpu43p firmware · omron/cj1g-cpu42p firmware · omron/cp1e-e firmware · omron/cp1e-n firmware · omron/cj2h-cpu68 firmware · omron/cj2h-cpu67 firmware · omron/cj2h-cpu66 firmware · omron/cj2h-cpu65 firmware · omron/cj2h-cpu64 firmware · omron/cj2h-cpu68-eip firmware · omron/cj2h-cpu67-eip firmware · omron/cj2h-cpu66-eip firmware · omron/cj2h-cpu65-eip firmware · omron/cj2h-cpu64-eip firmware · omron/cj2m-cpu35 firmware · omron/cj2m-cpu34 firmware · omron/cj2m-cpu33 firmware · +26 more
- Source
- ot-cert@dragos.com
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-262-05Third Party Advisory, US Government Resource
- https://www.dragos.com/advisory/omron-plc-and-engineering-software-network-and-file-format-access/Third Party Advisory
- https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2023-010_en.pdfVendor Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-262-05Third Party Advisory, US Government Resource
- https://www.dragos.com/advisory/omron-plc-and-engineering-software-network-and-file-format-access/Third Party Advisory
- https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2023-010_en.pdfVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.