Insufficient verification of data authenticity in SYSMAC NX Series and SYSMAC NJ Series - CVE-2022-31206
Published: June 29, 2022
Vulnerability identifier: #VU64803
CSH Severity: Low
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31206
CWE-ID: CWE-345
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to compromsie the target system.
The vulnerability exists due to the logic that is downloaded to the PLC is not cryptographically authenticated. A remote administrator can manipulate transmitted object code to the PLC and execute arbitrary machine code on the processor of the PLC's CPU module.
Affected software
SYSMAC NX Series
SYSMAC NJ Series
SYSMAC NJ Series
How to mitigate CVE-2022-31206
Install updates from vendor's website.
SYSMAC NX Series - addressed in versions 1.29, 1.49
SYSMAC NJ Series - update to 1.49
SYSMAC NJ Series - update to 1.49