Omron CS series, CJ series, and CP series PLCs through 2022-05-18 use cleartext passwords. They feature a UM Protection setting that allows users or system integrators to configure a password in order to restrict sensitive engineering operations (such as project/logic uploads and downloads). This password is set using the OMRON FINS command Program Area Protect and unset using the command Program Area Protect Clear, both of which are transmitted in cleartext.

Project Subscriptions

Vendors Products
Cp1w-cif41 Subscribe
Cp1w-cif41 Firmware Subscribe
Cx-programmer Subscribe
Sysmac Cj2h Subscribe
Sysmac Cj2h Firmware Subscribe
Sysmac Cj2m Subscribe
Sysmac Cj2m Firmware Subscribe
Sysmac Cp1e Subscribe
Sysmac Cp1e Firmware Subscribe
Sysmac Cp1h Subscribe
Sysmac Cp1h Firmware Subscribe
Sysmac Cp1l Subscribe
Sysmac Cp1l Firmware Subscribe
Sysmac Cs1 Subscribe
Sysmac Cs1 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-52788 Omron CS series, CJ series, and CP series PLCs through 2022-05-18 use cleartext passwords. They feature a UM Protection setting that allows users or system integrators to configure a password in order to restrict sensitive engineering operations (such as project/logic uploads and downloads). This password is set using the OMRON FINS command Program Area Protect and unset using the command Program Area Protect Clear, both of which are transmitted in cleartext.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T07:11:39.640Z

Reserved: 2022-05-18T00:00:00

Link: CVE-2022-31204

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-07-26T22:15:11.317

Modified: 2024-11-21T07:04:07.190

Link: CVE-2022-31204

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses