CVE-2022-31204: High severity omron sysmac cs1 firmware vulnerability
Omron CS series, CJ series, and CP series PLCs through 2022-05-18 use cleartext passwords. They feature a UM Protection setting that allows users or system integrators to configure a password in order to restrict sensitive engineering operations (such as project/logic uploads and downloads). This password is set using the OMRON FINS command Program Area Protect and unset using the command Program Area Protect Clear, both of which are transmitted in cleartext.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-31204?
CVE-2022-31204 refers to a vulnerability where Omron CS series, CJ series, and CP series PLCs use cleartext passwords, which can be exploited to gain unauthorized access.
How severe is CVE-2022-31204?
CVE-2022-31204 has a severity rating of 7.5 out of 10, indicating a high severity.
Which Omron PLCs are affected by CVE-2022-31204?
Omron CS series, CJ series, and CP series PLCs are affected by CVE-2022-31204.
What is the UM Protection setting in the affected Omron PLCs?
The UM Protection setting in the affected Omron PLCs allows users or system integrators to configure a password to restrict sensitive engineering operations.
How can CVE-2022-31204 be fixed?
To fix CVE-2022-31204, it is recommended to update the firmware of the affected Omron PLCs to a version that addresses the cleartext password vulnerability.