CVE-2022-31204
Summary
| CVE | CVE-2022-31204 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-26 22:15:00 UTC |
| Updated | 2022-08-04 14:59:00 UTC |
| Description | Omron CS series, CJ series, and CP series PLCs through 2022-05-18 use cleartext passwords. They feature a UM Protection setting that allows users or system integrators to configure a password in order to restrict sensitive engineering operations (such as project/logic uploads and downloads). This password is set using the OMRON FINS command Program Area Protect and unset using the command Program Area Protect Clear, both of which are transmitted in cleartext. |
Risk And Classification
Problem Types: CWE-319
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Omron | Cp1w-cif41 | - | All | All | All |
| Operating System | Omron | Cp1w-cif41 Firmware | - | All | All | All |
| Application | Omron | Cx-programmer | All | All | All | All |
| Hardware | Omron | Sysmac Cj2h | - | All | All | All |
| Operating System | Omron | Sysmac Cj2h Firmware | All | All | All | All |
| Hardware | Omron | Sysmac Cj2m | - | All | All | All |
| Operating System | Omron | Sysmac Cj2m Firmware | All | All | All | All |
| Hardware | Omron | Sysmac Cp1e | - | All | All | All |
| Operating System | Omron | Sysmac Cp1e Firmware | All | All | All | All |
| Hardware | Omron | Sysmac Cp1h | - | All | All | All |
| Operating System | Omron | Sysmac Cp1h Firmware | All | All | All | All |
| Hardware | Omron | Sysmac Cp1l | - | All | All | All |
| Operating System | Omron | Sysmac Cp1l Firmware | All | All | All | All |
| Hardware | Omron | Sysmac Cs1 | - | All | All | All |
| Operating System | Omron | Sysmac Cs1 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Omron SYSMAC CS/CJ/CP Series and NJ/NX Series | CISA | MISC | www.cisa.gov | |
| Blog - Forescout | MISC | www.forescout.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 591099 Omron SYSMAC CS/CJ/CP Series and NJ/NX Series Multiple Vulnerabilities (icsa-22-179-02)