ZeroHour

CVE-2022-31205

CVSS 3.1
7.5 high
EPSS
<1%p48
Published
()
Modified
Description

In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in memory area D1449...D1452 and can be read out using the Omron FINS protocol without any further authentication.

Vendors
omron
Products
sysmac cs1 firmware, sysmac cj2m firmware, sysmac cj2h firmware, sysmac cp1e firmware, sysmac cp1h firmware, sysmac cp1l firmware, cp1w-cif41 firmware
Weakness
CWE-312
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.