In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in memory area D1449...D1452 and can be read out using the Omron FINS protocol without any further authentication.

Project Subscriptions

Vendors Products
Cp1w-cif41 Subscribe
Cp1w-cif41 Firmware Subscribe
Sysmac Cj2h Subscribe
Sysmac Cj2h Firmware Subscribe
Sysmac Cj2m Subscribe
Sysmac Cj2m Firmware Subscribe
Sysmac Cp1e Subscribe
Sysmac Cp1e Firmware Subscribe
Sysmac Cp1h Subscribe
Sysmac Cp1h Firmware Subscribe
Sysmac Cp1l Subscribe
Sysmac Cp1l Firmware Subscribe
Sysmac Cs1 Subscribe
Sysmac Cs1 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-52789 In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in memory area D1449...D1452 and can be read out using the Omron FINS protocol without any further authentication.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T07:11:39.641Z

Reserved: 2022-05-18T00:00:00

Link: CVE-2022-31205

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-07-26T22:15:11.357

Modified: 2024-11-21T07:04:07.353

Link: CVE-2022-31205

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses