CVE-2022-31204
—CVSS 3.1
7.5 high
EPSS
<1%p48
Published
()
Modified
Description
Omron CS series, CJ series, and CP series PLCs through 2022-05-18 use cleartext passwords. They feature a UM Protection setting that allows users or system integrators to configure a password in order to restrict sensitive engineering operations (such as project/logic uploads and downloads). This password is set using the OMRON FINS command Program Area Protect and unset using the command Program Area Protect Clear, both of which are transmitted in cleartext.
- Vendors
- omron
- Products
- sysmac cs1 firmware, sysmac cj2m firmware, sysmac cj2h firmware, sysmac cp1e firmware, sysmac cp1h firmware, sysmac cp1l firmware, cp1w-cif41 firmware, cx-programmer
- Weakness
- CWE-319
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.