CVE-2023-0811

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
16/03/2023
Last modified:
07/11/2023

Description

<br /> Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an adversary issues a PROGRAM AREA WRITE command to a specific memory region, they could overwrite the password. This may lead to disabling UM protections or setting a non-ASCII password (non-keyboard characters) and preventing an engineer from viewing or modifying the user program. <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:omron:sysmac_cj2h-cpu64_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:omron:sysmac_cj2h-cpu64:-:*:*:*:*:*:*:*
cpe:2.3:o:omron:sysmac_cj2h-cpu64-eip_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:omron:sysmac_cj2h-cpu64-eip:-:*:*:*:*:*:*:*
cpe:2.3:o:omron:sysmac_cj2h-cpu65_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:omron:sysmac_cj2h-cpu65:-:*:*:*:*:*:*:*
cpe:2.3:o:omron:sysmac_cj2h-cpu65-eip_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:omron:sysmac_cj2h-cpu65-eip:-:*:*:*:*:*:*:*
cpe:2.3:o:omron:sysmac_cj2h-cpu66_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:omron:sysmac_cj2h-cpu66:-:*:*:*:*:*:*:*
cpe:2.3:o:omron:sysmac_cj2h-cpu66-eip_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:omron:sysmac_cj2h-cpu66-eip:-:*:*:*:*:*:*:*
cpe:2.3:o:omron:sysmac_cj2h-cpu67_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:omron:sysmac_cj2h-cpu67:-:*:*:*:*:*:*:*
cpe:2.3:o:omron:sysmac_cj2h-cpu67-eip_firmware:-:*:*:*:*:*:*:*