9.1

CVE-2022-45790

The Omron FINS protocol has an authenticated feature to prevent access to memory regions. Authentication is susceptible to bruteforce attack, which may allow an adversary to gain access to protected memory. This access can allow overwrite of values including programmed logic.

Data is provided by the National Vulnerability Database (NVD)
OmronCj1g-cpu45p Firmware Version < 4.1
   OmronCj1g-cpu45p Version-
OmronCj1g-cpu45p-gtc Firmware Version < 4.1
   OmronCj1g-cpu45p-gtc Version-
OmronCj1g-cpu44p Firmware Version < 4.1
   OmronCj1g-cpu44p Version-
OmronCj1g-cpu43p Firmware Version < 4.1
   OmronCj1g-cpu43p Version-
OmronCj1g-cpu42p Firmware Version < 4.1
   OmronCj1g-cpu42p Version-
OmronCp1e-e Firmware Version < 1.3
   OmronCp1e-e Version-
OmronCp1e-n Firmware Version < 1.3
   OmronCp1e-n Version-
OmronCj2h-cpu68 Firmware Version < 1.5
   OmronCj2h-cpu68 Version-
OmronCj2h-cpu67 Firmware Version < 1.5
   OmronCj2h-cpu67 Version-
OmronCj2h-cpu66 Firmware Version < 1.5
   OmronCj2h-cpu66 Version-
OmronCj2h-cpu65 Firmware Version < 1.5
   OmronCj2h-cpu65 Version-
OmronCj2h-cpu64 Firmware Version < 1.5
   OmronCj2h-cpu64 Version-
OmronCj2h-cpu68-eip Firmware Version < 1.5
   OmronCj2h-cpu68-eip Version-
OmronCj2h-cpu67-eip Firmware Version < 1.5
   OmronCj2h-cpu67-eip Version-
OmronCj2h-cpu66-eip Firmware Version < 1.5
   OmronCj2h-cpu66-eip Version-
OmronCj2h-cpu65-eip Firmware Version < 1.5
   OmronCj2h-cpu65-eip Version-
OmronCj2h-cpu64-eip Firmware Version < 1.5
   OmronCj2h-cpu64-eip Version-
OmronCj2m-cpu35 Firmware Version < 2.1
   OmronCj2m-cpu35 Version-
OmronCj2m-cpu34 Firmware Version < 2.1
   OmronCj2m-cpu34 Version-
OmronCj2m-cpu33 Firmware Version < 2.1
   OmronCj2m-cpu33 Version-
OmronCj2m-cpu32 Firmware Version < 2.1
   OmronCj2m-cpu32 Version-
OmronCj2m-cpu31 Firmware Version < 2.1
   OmronCj2m-cpu31 Version-
OmronCj2m-cpu15 Firmware Version < 2.1
   OmronCj2m-cpu15 Version-
OmronCj2m-cpu14 Firmware Version < 2.1
   OmronCj2m-cpu14 Version-
OmronCj2m-cpu13 Firmware Version < 2.1
   OmronCj2m-cpu13 Version-
OmronCj2m-cpu12 Firmware Version < 2.1
   OmronCj2m-cpu12 Version-
OmronCj2m-cpu11 Firmware Version < 2.1
   OmronCj2m-cpu11 Version-
OmronCj2m-md211 Firmware Version < 2.1
   OmronCj2m-md211 Version-
OmronCj2m-md212 Firmware Version < 2.1
   OmronCj2m-md212 Version-
OmronCs1d-cpu67s Firmware Version < 2.1
   OmronCs1d-cpu67s Version-
OmronCs1d-cpu65s Firmware Version < 2.1
   OmronCs1d-cpu65s Version-
OmronCs1d-cpu44s Firmware Version < 2.1
   OmronCs1d-cpu44s Version-
OmronCs1d-cpu42s Firmware Version < 2.1
   OmronCs1d-cpu42s Version-
OmronCs1d-cpu65p Firmware Version < 1.4
   OmronCs1d-cpu65p Version-
OmronCs1d-cpu67p Firmware Version < 1.4
   OmronCs1d-cpu67p Version-
OmronCs1d-cpu67h Firmware Version < 1.4
   OmronCs1d-cpu67h Version-
OmronCs1d-cpu65h Firmware Version < 1.4
   OmronCs1d-cpu65h Version-
OmronCs1h-cpu67h Firmware Version < 4.1
   OmronCs1h-cpu67h Version-
OmronCs1h-cpu66h Firmware Version < 4.1
   OmronCs1h-cpu66h Version-
OmronCs1h-cpu65h Firmware Version < 4.1
   OmronCs1h-cpu65h Version-
OmronCs1h-cpu64h Firmware Version < 4.1
   OmronCs1h-cpu64h Version-
OmronCs1h-cpu63h Firmware Version < 4.1
   OmronCs1h-cpu63h Version-
OmronCs1g-cpu45h Firmware Version < 4.1
   OmronCs1g-cpu45h Version-
OmronCs1g-cpu44h Firmware Version < 4.1
   OmronCs1g-cpu44h Version-
OmronCs1g-cpu43h Firmware Version < 4.1
   OmronCs1g-cpu43h Version-
OmronCs1g-cpu42h Firmware Version < 4.1
   OmronCs1g-cpu42h Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.39% 0.57
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
ot-cert@dragos.com 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
CWE-307 Improper Restriction of Excessive Authentication Attempts

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.