Insufficient verification of data authenticity in Omron products - CVE-2022-31207

 

Insufficient verification of data authenticity in Omron products - CVE-2022-31207

Published: June 29, 2022


Vulnerability identifier: #VU64802
CSH Severity: Low
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31207
CWE-ID: CWE-345
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromsie the target system.

The vulnerability exists due to the logic that is downloaded to the PLC is not cryptographically authenticated. A remote administrator can execute arbitrary object code commands on the defined software logic.


Affected software

SYSMAC CJ2H
SYSMAC CP1L
SYSMAC CP1E
SYSMAC CP1H
SYSMAC CJ2M
SYSMAC CS1

How to mitigate CVE-2022-31207

Install updates from vendor's website.

SYSMAC CJ2H - update to 1.5
SYSMAC CP1L - update to 1.10
SYSMAC CP1E - update to 1.30
SYSMAC CP1H - update to 1.30
SYSMAC CJ2M - update to 2.1
SYSMAC CS1 - update to 4.1

External References

Related Security Bulletins