Description
Omron CS series, CJ series, and CP series PLCs through 2022-05-18 use cleartext passwords. They feature a UM Protection setting that allows users or system integrators to configure a password in order to restrict sensitive engineering operations (such as project/logic uploads and downloads). This password is set using the OMRON FINS command Program Area Protect and unset using the command Program Area Protect Clear, both of which are transmitted in cleartext.
Published: 2022-07-26
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-52788 Omron CS series, CJ series, and CP series PLCs through 2022-05-18 use cleartext passwords. They feature a UM Protection setting that allows users or system integrators to configure a password in order to restrict sensitive engineering operations (such as project/logic uploads and downloads). This password is set using the OMRON FINS command Program Area Protect and unset using the command Program Area Protect Clear, both of which are transmitted in cleartext.
History

No history.

Subscriptions

Omron Cp1w-cif41 Cp1w-cif41 Firmware Cx-programmer Sysmac Cj2h Sysmac Cj2h Firmware Sysmac Cj2m Sysmac Cj2m Firmware Sysmac Cp1e Sysmac Cp1e Firmware Sysmac Cp1h Sysmac Cp1h Firmware Sysmac Cp1l Sysmac Cp1l Firmware Sysmac Cs1 Sysmac Cs1 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T07:11:39.640Z

Reserved: 2022-05-18T00:00:00.000Z

Link: CVE-2022-31204

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-07-26T22:15:11.317

Modified: 2024-11-21T07:04:07.190

Link: CVE-2022-31204

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses