8.6
CVE-2022-45794
- EPSS 0.54%
- Veröffentlicht 10.01.2024 23:15:08
- Zuletzt bearbeitet 21.11.2024 07:29:43
- Quelle ot-cert@dragos.com
- CVE-Watchlists
- Unerledigt
Omron CJ-series and CS-series unauthenticated filesystem access.
An attacker with network access to the affected PLC (CJ-series and CS-series PLCs, all versions) may use a network protocol to read and write files on the PLC internal memory and memory card.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Omron ≫ Sysmac Cj2h-cpu64-eip Firmware Version-
Omron ≫ Sysmac Cj2h-cpu64 Firmware Version-
Omron ≫ Sysmac Cj2h-cpu65-eip Firmware Version-
Omron ≫ Sysmac Cj2h-cpu65 Firmware Version-
Omron ≫ Sysmac Cj2h-cpu66-eip Firmware Version-
Omron ≫ Sysmac Cj2h-cpu66 Firmware Version-
Omron ≫ Sysmac Cj2h-cpu67-eip Firmware Version-
Omron ≫ Sysmac Cj2h-cpu67 Firmware Version-
Omron ≫ Sysmac Cj2h-cpu68-eip Firmware Version-
Omron ≫ Sysmac Cj2h-cpu68 Firmware Version-
Omron ≫ Sysmac Cj2m-cpu11 Firmware Version-
Omron ≫ Sysmac Cj2m-cpu12 Firmware Version-
Omron ≫ Sysmac Cj2m-cpu13 Firmware Version-
Omron ≫ Sysmac Cj2m-cpu14 Firmware Version-
Omron ≫ Sysmac Cj2m-cpu15 Firmware Version-
Omron ≫ Sysmac Cj2m-cpu31 Firmware Version-
Omron ≫ Sysmac Cj2m-cpu32 Firmware Version-
Omron ≫ Sysmac Cj2m-cpu33 Firmware Version-
Omron ≫ Sysmac Cj2m-cpu34 Firmware Version-
Omron ≫ Sysmac Cj2m-cpu35 Firmware Version-
Omron ≫ Sysmac Cj1g-cpu45p Firmware Version-
Omron ≫ Sysmac Cj1g-cpu44p Firmware Version-
Omron ≫ Sysmac Cj1g-cpu43p Firmware Version-
Omron ≫ Sysmac Cj1g-cpu42p Firmware Version-
Omron ≫ Sysmac Cs1h-cpu63h Firmware Version-
Omron ≫ Sysmac Cs1h-cpu65h Firmware Version-
Omron ≫ Sysmac Cs1h-cpu67h Firmware Version-
Omron ≫ Sysmac Cs1h-cpu64h Firmware Version-
Omron ≫ Sysmac Cs1h-cpu66h Firmware Version-
Omron ≫ Sysmac Cs1g-cpu44h Firmware Version-
Omron ≫ Sysmac Cs1g-cpu43h Firmware Version-
Omron ≫ Sysmac Cs1g-cpu42h Firmware Version-
Omron ≫ Sysmac Cs1g-cpu45h Firmware Version-
Omron ≫ Sysmac Cs1d-cpu65h Firmware Version-
Omron ≫ Sysmac Cs1d-cpu67h Firmware Version-
Omron ≫ Sysmac Cs1d-cpu68ha Firmware Version-
Omron ≫ Sysmac Cs1d-cpu67ha Firmware Version-
Omron ≫ Sysmac Cs1d-cpu65p Firmware Version-
Omron ≫ Sysmac Cs1d-cpu67sa Firmware Version-
Omron ≫ Sysmac Cs1d-cpu44sa Firmware Version-
Omron ≫ Sysmac Cs1d-cpu67p Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.54% | 0.408 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| ot-cert@dragos.com | 8.6 | 3.9 | 4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
https://www.dragos.com/advisory/omron-plc-and-engineering-software-network-and-file-format-access/
https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2023-002_en.pdf