CVE-2023-0811
Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.62%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an adversary issues a PROGRAM AREA WRITE command to a specific memory region, they could overwrite the password. This may lead to disabling UM protections or setting a non-ASCII password (non-keyboard characters) and preventing an engineer from viewing or modifying the user program.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- EPSS
- 0.62% probability · 48th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- omron/sysmac cj2h-cpu64 firmware · omron/sysmac cj2h-cpu64-eip firmware · omron/sysmac cj2h-cpu65 firmware · omron/sysmac cj2h-cpu65-eip firmware · omron/sysmac cj2h-cpu66 firmware · omron/sysmac cj2h-cpu66-eip firmware · omron/sysmac cj2h-cpu67 firmware · omron/sysmac cj2h-cpu67-eip firmware · omron/sysmac cj2h-cpu68 firmware · omron/sysmac cj2h-cpu68-eip firmware · omron/sysmac cj2m-cpu11 firmware · omron/sysmac cj2m-cpu12 firmware · omron/sysmac cj2m-cpu13 firmware · omron/sysmac cj2m-cpu14 firmware · omron/sysmac cj2m-cpu15 firmware · omron/sysmac cj2m-cpu31 firmware · omron/sysmac cj2m-cpu32 firmware · omron/sysmac cj2m-cpu33 firmware · omron/sysmac cj2m-cpu34 firmware · omron/sysmac cj2m-cpu35 firmware · +40 more
- Source
- ics-cert@hq.dhs.gov
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-073-01Third Party Advisory, US Government Resource
- https://www.ia.omron.com/product/vulnerability/OMSR-2023-001_en.pdfMitigation, Vendor Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-073-01Third Party Advisory, US Government Resource
- https://www.ia.omron.com/product/vulnerability/OMSR-2023-001_en.pdfMitigation, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.