#VU23585 Authentication Bypass by Capture-replay in Omron PLC CS series and Omron PLC CJ series - CVE-2019-13533
Published: December 13, 2019
Omron PLC CS series
Omron PLC CJ series
Omron
Description
The vulnerability allows a remote attacker to bypass authentication on the target system.
The vulnerability exists in the FINS communication protocol due to the FINS communication packet between a controller and a PLC may be monitored and it may invite replay attack using commands for the PLC. A remote attacker can cause opening and closing of industrial valves.