9.1

CVE-2023-0811

Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an adversary issues a PROGRAM AREA WRITE command to a specific memory region, they could overwrite the password. This may lead to disabling UM protections or setting a non-ASCII password (non-keyboard characters) and preventing an engineer from viewing or modifying the user program. 

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OmronSysmac Cj2h-cpu64 Firmware Version-
   OmronSysmac Cj2h-cpu64 Version-
OmronSysmac Cj2h-cpu65 Firmware Version-
   OmronSysmac Cj2h-cpu65 Version-
OmronSysmac Cj2h-cpu66 Firmware Version-
   OmronSysmac Cj2h-cpu66 Version-
OmronSysmac Cj2h-cpu67 Firmware Version-
   OmronSysmac Cj2h-cpu67 Version-
OmronSysmac Cj2h-cpu68 Firmware Version-
   OmronSysmac Cj2h-cpu68 Version-
OmronSysmac Cj2m-cpu11 Firmware Version-
   OmronSysmac Cj2m-cpu11 Version-
OmronSysmac Cj2m-cpu12 Firmware Version-
   OmronSysmac Cj2m-cpu12 Version-
OmronSysmac Cj2m-cpu13 Firmware Version-
   OmronSysmac Cj2m-cpu13 Version-
OmronSysmac Cj2m-cpu14 Firmware Version-
   OmronSysmac Cj2m-cpu14 Version-
OmronSysmac Cj2m-cpu15 Firmware Version-
   OmronSysmac Cj2m-cpu15 Version-
OmronSysmac Cj2m-cpu31 Firmware Version-
   OmronSysmac Cj2m-cpu31 Version-
OmronSysmac Cj2m-cpu32 Firmware Version-
   OmronSysmac Cj2m-cpu32 Version-
OmronSysmac Cj2m-cpu33 Firmware Version-
   OmronSysmac Cj2m-cpu33 Version-
OmronSysmac Cj2m-cpu34 Firmware Version-
   OmronSysmac Cj2m-cpu34 Version-
OmronSysmac Cj2m-cpu35 Firmware Version-
   OmronSysmac Cj2m-cpu35 Version-
OmronSysmac Cs1w-eip21 Firmware Version-
   OmronSysmac Cs1w-eip21 Version-
OmronSysmac Cs1w-etn21 Firmware Version-
   OmronSysmac Cs1w-etn21 Version-
OmronSysmac Cs1w-fln22 Firmware Version-
   OmronSysmac Cs1w-fln22 Version-
OmronSysmac Cs1w-nc[]71 Firmware Version-
   OmronSysmac Cs1w-nc[]71 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.302
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
ics-cert@hq.dhs.gov 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.