SB2022062925 - Unprotected storage of credentials in Omron CP1W-CIF41
Published: June 29, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Unprotected storage of credentials (CVE-ID: CVE-2022-31205)
The vulnerability allows a remote attacker to gain access to other users' credentials.
The vulnerability exists due to a Web UI password can be read from memory using the Omron FINS protocol. A remote attacker can gain access to passwords for 3rd party integration.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.