7.5

CVE-2022-31205

In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in memory area D1449...D1452 and can be read out using the Omron FINS protocol without any further authentication.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OmronSysmac Cs1 Firmware Version < 4.1
   OmronSysmac Cs1 Version-
OmronSysmac Cj2m Firmware Version < 2.1
   OmronSysmac Cj2m Version-
OmronSysmac Cj2h Firmware Version < 1.5
   OmronSysmac Cj2h Version-
OmronSysmac Cp1e Firmware Version < 1.30
   OmronSysmac Cp1e Version-
OmronSysmac Cp1h Firmware Version < 1.30
   OmronSysmac Cp1h Version-
OmronSysmac Cp1l Firmware Version < 1.10
   OmronSysmac Cp1l Version-
OmronCp1w-cif41 Firmware Version-
   OmronCp1w-cif41 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.09% 0.258
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-312 Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.