QID 591349

Date Published: 2023-02-17

QID 591349: Omron CP1L-EL20DR-D Active debug code Vulnerability (JVNVU97575890)

AFFECTED PRODUCTS
Programmable Logic Controller (PLC) CP1L Series
CP1L-EL20DR-D all versions

QID Detection Logic:
This QID checks for the Vulnerable version of Omron CP1L-EL20DR-D using passive scanning

A remote unauthenticated attacker may read/write in arbitrary area of the device memory, which may lead to overwriting the firmware, causing a denial-of-service (DoS) condition, and/or arbitrary code execution.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section JVNVU97575890 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591349

    Software Advisories
    Advisory ID Software Component Link
    JVNVU97575890 URL Logo jvn.jp/en/vu/JVNVU97575890/index.html