CVE-2023-27396
When arbitrary FINS messages are injected, any commands may be executed on, or the system information may be retrieved from, the affected device.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.37%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation) networks, and is used in FA networks composed of OMRON products. Multiple OMRON products that implement FINS protocol contain following security issues -- (1)Plaintext communication, and (2)No authentication required. When FINS messages are intercepted, the contents may be retrieved. When arbitrary FINS messages are injected, any commands may be executed on, or the system information may be retrieved from, the affected device. Affected products and versions are as follows: SYSMAC CS-series CPU Units, all versions, SYSMAC CJ-series CPU Units, all versions, SYSMAC CP-series CPU Units, all versions, SYSMAC NJ-series CPU Units, all versions, SYSMAC NX1P-series CPU Units, all versions, SYSMAC NX102-series CPU Units, all versions, and SYSMAC NX7 Database Connection CPU Units (Ver.1.16 or later)
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.37% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- omron/cs1w-eip21 firmware · omron/cs1w-spu01-v2 firmware · omron/cs1w-spu02-v2 firmware · omron/cs1w-etn21 firmware · omron/cs1w-clk firmware · omron/cs1w-fln22 firmware · omron/cs1w-drm21-v1 firmware · omron/cs1w-nc271 firmware · omron/cs1w-nc471 firmware · omron/cs1w-ncf71 firmware · omron/cj2m-cpu35 firmware · omron/cj2m-cpu34 firmware · omron/cj2m-cpu33 firmware · omron/cj2m-cpu32 firmware · omron/cj2m-cpu31 firmware · omron/cj2m-cpu15 firmware · omron/cj2m-cpu14 firmware · omron/cj2m-cpu13 firmware · omron/cj2m-cpu12 firmware · omron/cj2m-cpu11 firmware · +40 more
- Source
- vultures@jpcert.or.jp
References
- https://jvn.jp/en/ta/JVNTA91513661/Third Party Advisory
- https://jvn.jp/ta/JVNTA91513661/Third Party Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-179-02Not Applicable, Third Party Advisory, US Government Resource
- https://www.fa.omron.co.jp/product/vulnerability/OMSR-2023-003_ja.pdfVendor Advisory
- https://www.ia.omron.com/product/vulnerability/OMSR-2023-003_en.pdfVendor Advisory
- https://www.us-cert.gov/ics/advisories/icsa-19-346-02Not Applicable, Third Party Advisory, US Government Resource
- https://www.us-cert.gov/ics/advisories/icsa-20-063-03Not Applicable, Third Party Advisory, US Government Resource
- https://jvn.jp/en/ta/JVNTA91513661/Third Party Advisory
- https://jvn.jp/ta/JVNTA91513661/Third Party Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-179-02Not Applicable, Third Party Advisory, US Government Resource
- https://www.fa.omron.co.jp/product/vulnerability/OMSR-2023-003_ja.pdfVendor Advisory
- https://www.ia.omron.com/product/vulnerability/OMSR-2023-003_en.pdfVendor Advisory
- https://www.us-cert.gov/ics/advisories/icsa-19-346-02Not Applicable, Third Party Advisory, US Government Resource
- https://www.us-cert.gov/ics/advisories/icsa-20-063-03Not Applicable, Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.