8.6

CVE-2022-45794

An attacker with network access to the affected PLC (CJ-series and CS-series PLCs, all versions) may use a network protocol to read and write files on the PLC internal memory and memory card.

Data is provided by the National Vulnerability Database (NVD)
OmronSysmac Cj2h-cpu64 Firmware Version-
   OmronSysmac Cj2h-cpu64 Version-
OmronSysmac Cj2h-cpu65 Firmware Version-
   OmronSysmac Cj2h-cpu65 Version-
OmronSysmac Cj2h-cpu66 Firmware Version-
   OmronSysmac Cj2h-cpu66 Version-
OmronSysmac Cj2h-cpu67 Firmware Version-
   OmronSysmac Cj2h-cpu67 Version-
OmronSysmac Cj2h-cpu68 Firmware Version-
   OmronSysmac Cj2h-cpu68 Version-
OmronSysmac Cj2m-cpu11 Firmware Version-
   OmronSysmac Cj2m-cpu11 Version-
OmronSysmac Cj2m-cpu12 Firmware Version-
   OmronSysmac Cj2m-cpu12 Version-
OmronSysmac Cj2m-cpu13 Firmware Version-
   OmronSysmac Cj2m-cpu13 Version-
OmronSysmac Cj2m-cpu14 Firmware Version-
   OmronSysmac Cj2m-cpu14 Version-
OmronSysmac Cj2m-cpu15 Firmware Version-
   OmronSysmac Cj2m-cpu15 Version-
OmronSysmac Cj2m-cpu31 Firmware Version-
   OmronSysmac Cj2m-cpu31 Version-
OmronSysmac Cj2m-cpu32 Firmware Version-
   OmronSysmac Cj2m-cpu32 Version-
OmronSysmac Cj2m-cpu33 Firmware Version-
   OmronSysmac Cj2m-cpu33 Version-
OmronSysmac Cj2m-cpu34 Firmware Version-
   OmronSysmac Cj2m-cpu34 Version-
OmronSysmac Cj2m-cpu35 Firmware Version-
   OmronSysmac Cj2m-cpu35 Version-
OmronSysmac Cj1g-cpu45p Firmware Version-
   OmronSysmac Cj1g-cpu45p Version-
OmronSysmac Cj1g-cpu44p Firmware Version-
   OmronSysmac Cj1g-cpu44p Version-
OmronSysmac Cj1g-cpu43p Firmware Version-
   OmronSysmac Cj1g-cpu43p Version-
OmronSysmac Cj1g-cpu42p Firmware Version-
   OmronSysmac Cj1g-cpu42p Version-
OmronSysmac Cs1h-cpu63h Firmware Version-
   OmronSysmac Cs1h-cpu63h Version-
OmronSysmac Cs1h-cpu65h Firmware Version-
   OmronSysmac Cs1h-cpu65h Version-
OmronSysmac Cs1h-cpu67h Firmware Version-
   OmronSysmac Cs1h-cpu67h Version-
OmronSysmac Cs1h-cpu64h Firmware Version-
   OmronSysmac Cs1h-cpu64h Version-
OmronSysmac Cs1h-cpu66h Firmware Version-
   OmronSysmac Cs1h-cpu66h Version-
OmronSysmac Cs1g-cpu44h Firmware Version-
   OmronSysmac Cs1g-cpu44h Version-
OmronSysmac Cs1g-cpu43h Firmware Version-
   OmronSysmac Cs1g-cpu43h Version-
OmronSysmac Cs1g-cpu42h Firmware Version-
   OmronSysmac Cs1g-cpu42h Version-
OmronSysmac Cs1g-cpu45h Firmware Version-
   OmronSysmac Cs1g-cpu45h Version-
OmronSysmac Cs1d-cpu65h Firmware Version-
   OmronSysmac Cs1d-cpu65h Version-
OmronSysmac Cs1d-cpu67h Firmware Version-
   OmronSysmac Cs1d-cpu67h Version-
OmronSysmac Cs1d-cpu65p Firmware Version-
   OmronSysmac Cs1d-cpu65p Version-
OmronSysmac Cs1d-cpu67p Firmware Version-
   OmronSysmac Cs1d-cpu67p Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.16% 0.38
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
ot-cert@dragos.com 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.