| [Japanese] | |
JVNDB-2023-001005 | |
Active debug code vulnerability in OMRON CP1L-EL20DR-D | |
| Overview | |
Active debug code (CWE-489) exists in CP1L-EL20DR-D provided by OMRON Corporation, which may lead to a command that is not specified in FINS protocol being executed without authentication. | |
| CVSS Severity (What is CVSS?) | |
|
CVSS V3 Severity:
Base Metrics 9.1 (Critical) [Other]
| |
| Affected Products | |
* Programmable Logic Controller (PLC) CP1L Series | |
OMRON Corporation | |
To check the product names and versions, refer to the manual "CP Series CP1L-EL/EM CPU Unit User's Manual (SBCA-406)" provided by the developer. | |
| Impact | |
A remote unauthenticated attacker may read/write in arbitrary area of the device memory, which may lead to overwriting the firmware, causing a denial-of-service (DoS) condition, and/or arbitrary code execution. | |
| Solution | |
[Update the product and enable "Extend protection password" function] | |
| Vendor Information | |
OMRON Corporation | |
| CWE (What is CWE?) | |
| |
| CVE (What is CVE?) | |
|
| |
| References | |
| |
| Revision History | |
|
| Date Public | 2023/01/11 |
| Date First Published | 2023/01/12 |
| Date Last Updated | 2023/01/12 |


