QID 591099

Date Published: 2022-10-14

QID 591099: Omron SYSMAC CS/CJ/CP Series and NJ/NX Series Multiple Vulnerabilities (icsa-22-179-02)

AFFECTED PRODUTCS
The following versions of the Omron SYSMAC CS/CJ/CP Series and NJ/NX Series, a programmable logic controller, are affected:
SYSMAC CS1: Versions prior to 4.1
SYSMAC CJ2M: Versions prior to 2.1
SYSMAC CJ2H: Versions prior to 1.5
SYSMAC CP1E/CP1H: Versions prior to 1.30
SYSMAC CP1L: Versions prior to 1.10
CP1W-CIF41: All versions
SYSMAC CX-Programmer: Versions prior to 9.6
SYSMAC NJ/NX Series: Versions prior to 1.49 (1.29 for NX7)

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of these vulnerabilities could cause a denial-of-service condition and allow remote code execution.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Low - 0 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section icsa-22-179-02 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591099

    Software Advisories
    Advisory ID Software Component Link
    icsa-22-179-02 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-179-02