CVE-2022-31205
Summary
| CVE | CVE-2022-31205 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-26 22:15:00 UTC |
| Updated | 2023-08-08 14:22:00 UTC |
| Description | In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in memory area D1449...D1452 and can be read out using the Omron FINS protocol without any further authentication. |
Risk And Classification
Problem Types: CWE-312
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Omron | Cp1w-cif41 | - | All | All | All |
| Operating System | Omron | Cp1w-cif41 Firmware | - | All | All | All |
| Hardware | Omron | Sysmac Cj2h | - | All | All | All |
| Operating System | Omron | Sysmac Cj2h Firmware | All | All | All | All |
| Hardware | Omron | Sysmac Cj2m | - | All | All | All |
| Operating System | Omron | Sysmac Cj2m Firmware | All | All | All | All |
| Hardware | Omron | Sysmac Cp1e | - | All | All | All |
| Operating System | Omron | Sysmac Cp1e Firmware | All | All | All | All |
| Hardware | Omron | Sysmac Cp1h | - | All | All | All |
| Operating System | Omron | Sysmac Cp1h Firmware | All | All | All | All |
| Hardware | Omron | Sysmac Cp1l | - | All | All | All |
| Operating System | Omron | Sysmac Cp1l Firmware | All | All | All | All |
| Hardware | Omron | Sysmac Cs1 | - | All | All | All |
| Operating System | Omron | Sysmac Cs1 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Omron SYSMAC CS/CJ/CP Series and NJ/NX Series | CISA | MISC | www.cisa.gov | |
| Blog - Forescout | MISC | www.forescout.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 591099 Omron SYSMAC CS/CJ/CP Series and NJ/NX Series Multiple Vulnerabilities (icsa-22-179-02)