CVE Feed

    Dashboard / CVE / CVE-2022-31205

    CVE-2022-31205

    In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in memory area D1449...D1452 and can be read out using the Omron FINS protocol without any further authentication.

    Published:Jul 26, 2022
    Last Modified:Nov 21, 2024
    EPS:Jul 26, 2022
    EPSS Score:0.00086
    CVSS Score:7.5

    Affected Products

    Vendor
    Omron
    Product
    Cp1w-cif41
    Vendor
    Omron
    Product
    Cp1w-cif41 Firmware
    Vendor
    Omron
    Product
    Sysmac Cj2h
    Vendor
    Omron
    Product
    Sysmac Cj2h Firmware
    Vendor
    Omron
    Product
    Sysmac Cj2m
    Vendor
    Omron
    Product
    Sysmac Cj2m Firmware
    Vendor
    Omron
    Product
    Sysmac Cp1e
    Vendor
    Omron
    Product
    Sysmac Cp1e Firmware
    Vendor
    Omron
    Product
    Sysmac Cp1h
    Vendor
    Omron
    Product
    Sysmac Cp1h Firmware
    Vendor
    Omron
    Product
    Sysmac Cp1l
    Vendor
    Omron
    Product
    Sysmac Cp1l Firmware
    Vendor
    Omron
    Product
    Sysmac Cs1
    Vendor
    Omron
    Product
    Sysmac Cs1 Firmware

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High