[Japanese] | |
JVNDB-2023-002787 | |
OMRON CJ series and CS/CJ Series EtherNet/IT unit vulnerable to Denial-of-Service (DoS) | |
Overview | |
Denial-of-service (DoS) vulnerability due to improper validation of specified type of input (CWE-1287) issue exists in the built-in EtherNet/IP port of the CJ Series CJ2 CPU unit and the communication function of the CS/CJ Series EtherNet/IP unit provided by OMRON Corporation. | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 7.5 (High) [Other]
| |
Affected Products | |
| |
OMRON Corporation | |
Regarding how to check the affected products/versions, refer to the manuals listed below. * CJ Series CPU Unit User's Manual (Hardware) (W472-E1-15) "Unit Versions of CJ2 CPU Units" section * CS/CJ Series EtherNet/IP Units Operation Manual (W465-E1-12) "Unit Versions of CS/CJ-series" section | |
Impact | |
If an affected product receives a packet which is specially crafted by a remote unauthenticated attacker, the unit of the affected product may fall into a denial-of-service (DoS) condition. | |
Solution | |
[Update the firmware] | |
Vendor Information | |
OMRON Corporation | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2023/08/01 |
Date First Published | 2023/08/03 |
Date Last Updated | 2023/08/03 |