[Japanese] | |
JVNDB-2023-001005 | |
Active debug code vulnerability in OMRON CP1L-EL20DR-D | |
Overview | |
Active debug code (CWE-489) exists in CP1L-EL20DR-D provided by OMRON Corporation, which may lead to a command that is not specified in FINS protocol being executed without authentication. | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 9.1 (Critical) [Other]
| |
Affected Products | |
* Programmable Logic Controller (PLC) CP1L Series | |
OMRON Corporation | |
To check the product names and versions, refer to the manual "CP Series CP1L-EL/EM CPU Unit User's Manual (SBCA-406)" provided by the developer. | |
Impact | |
A remote unauthenticated attacker may read/write in arbitrary area of the device memory, which may lead to overwriting the firmware, causing a denial-of-service (DoS) condition, and/or arbitrary code execution. | |
Solution | |
[Update the product and enable "Extend protection password" function] | |
Vendor Information | |
OMRON Corporation | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2023/01/11 |
Date First Published | 2023/01/12 |
Date Last Updated | 2023/01/12 |