Insufficient verification of data authenticity in SYSMAC NX Series and SYSMAC NJ Series - CVE-2022-31206

 

Insufficient verification of data authenticity in SYSMAC NX Series and SYSMAC NJ Series - CVE-2022-31206

Published: June 29, 2022


Vulnerability identifier: #VU64803
CSH Severity: Low
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31206
CWE-ID: CWE-345
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromsie the target system.

The vulnerability exists due to the logic that is downloaded to the PLC is not cryptographically authenticated. A remote administrator can manipulate transmitted object code to the PLC and execute arbitrary machine code on the processor of the PLC's CPU module.


Affected software

SYSMAC NX Series
SYSMAC NJ Series

How to mitigate CVE-2022-31206

Install updates from vendor's website.

SYSMAC NX Series - addressed in versions 1.29, 1.49
SYSMAC NJ Series - update to 1.49

External References

Related Security Bulletins