CVE-2022-45790: Omron FINS memory protection susceptible to bruteforce

Published Jan 22, 2024
·
Updated

The Omron FINS protocol has an authenticated feature to prevent access to memory regions. Authentication is susceptible to bruteforce attack, which may allow an adversary to gain access to protected memory. This access can allow overwrite of values including programmed logic.

Affected Software

92 affected components
All of the following
Omron Cj1g-cpu45p Firmware<4.1
Omron Cj1g-cpu45p
All of the following
Omron Cj1g-cpu45p-gtc Firmware<4.1
Omron Cj1g-cpu45p-gtc
All of the following
Omron Cj1g-cpu44p Firmware<4.1
Omron Cj1g-cpu44p
All of the following
Omron Cj1g-cpu43p Firmware<4.1
Omron Cj1g-cpu43p
All of the following
Omron Cj1g-cpu42p Firmware<4.1
Omron Cj1g-cpu42p
All of the following
Omron Cp1e-e Firmware<1.3
Omron Cp1e-e
All of the following
Omron Cp1e-n Firmware<1.3
Omron Cp1e-n
All of the following
Omron Cj2h-cpu68 Firmware<1.5
Omron Cj2h-cpu68
All of the following
Omron Cj2h-cpu67 Firmware<1.5
Omron Cj2h-cpu67
All of the following
Omron Cj2h-cpu66 Firmware<1.5
Omron Cj2h-cpu66
All of the following
Omron Cj2h-cpu65 Firmware<1.5
Omron Cj2h-cpu65
All of the following
Omron Cj2h-cpu64 Firmware<1.5
Omron Cj2h-cpu64
All of the following
Omron Cj2h-cpu68-eip Firmware<1.5
Omron Cj2h-cpu68-eip
All of the following
Omron Cj2h-cpu67-eip Firmware<1.5
Omron Cj2h-cpu67-eip
All of the following
Omron Cj2h-cpu66-eip Firmware<1.5
Omron Cj2h-cpu66-eip
All of the following
Omron Cj2h-cpu65-eip Firmware<1.5
Omron Cj2h-cpu65-eip
All of the following
Omron Cj2h-cpu64-eip Firmware<1.5
Omron Cj2h-cpu64-eip
All of the following
Omron Cj2m-cpu35 Firmware<2.1
Omron Cj2m-cpu35
All of the following
Omron Cj2m-cpu34 Firmware<2.1
Omron Cj2m-cpu34
All of the following
Omron Cj2m-cpu33 Firmware<2.1
Omron Cj2m-cpu33
All of the following
Omron Cj2m-cpu32 Firmware<2.1
Omron Cj2m-cpu32
All of the following
Omron Cj2m-cpu31 Firmware<2.1
Omron Cj2m-cpu31
All of the following
Omron Cj2m-cpu15 Firmware<2.1
Omron Cj2m-cpu15
All of the following
Omron Cj2m-cpu14 Firmware<2.1
Omron Cj2m-cpu14
All of the following
Omron Cj2m-cpu13 Firmware<2.1
Omron Cj2m-cpu13
All of the following
Omron Cj2m-cpu12 Firmware<2.1
Omron Cj2m-cpu12
All of the following
Omron Cj2m-cpu11 Firmware<2.1
Omron Cj2m-cpu11
All of the following
Omron Cj2m-md211 Firmware<2.1
Omron Cj2m-md211
All of the following
Omron Cj2m-md212 Firmware<2.1
Omron Cj2m-md212
All of the following
Omron Cs1d-cpu67s Firmware<2.1
Omron Cs1d-cpu67s
All of the following
Omron Cs1d-cpu65s Firmware<2.1
Omron Cs1d-cpu65s
All of the following
Omron Cs1d-cpu44s Firmware<2.1
Omron Cs1d-cpu44s
All of the following
Omron Cs1d-cpu42s Firmware<2.1
Omron Cs1d-cpu42s
All of the following
Omron Cs1d-cpu65p Firmware<1.4
Omron Cs1d-cpu65p
All of the following
Omron Cs1d-cpu67p Firmware<1.4
Omron Cs1d-cpu67p
All of the following
Omron Cs1d-cpu67h Firmware<1.4
Omron Cs1d-cpu67h
All of the following
Omron Cs1d-cpu65h Firmware<1.4
Omron Cs1d-cpu65h
All of the following
Omron Cs1h-cpu67h Firmware<4.1
Omron Cs1h-cpu67h
All of the following
Omron Cs1h-cpu66h Firmware<4.1
Omron Cs1h-cpu66h
All of the following
Omron Cs1h-cpu65h Firmware<4.1
Omron Cs1h-cpu65h
All of the following
Omron Cs1h-cpu64h Firmware<4.1
Omron Cs1h-cpu64h
All of the following
Omron Cs1h-cpu63h Firmware<4.1
Omron Cs1h-cpu63h
All of the following
Omron Cs1g-cpu45h Firmware<4.1
Omron Cs1g-cpu45h
All of the following
Omron Cs1g-cpu44h Firmware<4.1
Omron Cs1g-cpu44h
All of the following
Omron Cs1g-cpu43h Firmware<4.1
Omron Cs1g-cpu43h
All of the following
Omron Cs1g-cpu42h Firmware<4.1
Omron Cs1g-cpu42h

Event History

Jan 22, 2024
CVE Published
via MITRE·05:22 PM
Data Sourced
via MITRE·05:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2022-45790?

CVE-2022-45790 is classified as a high severity vulnerability due to its potential for unauthorized access and memory modification.

2

What devices are affected by CVE-2022-45790?

CVE-2022-45790 affects various Omron CJ series and CP series programmable controllers running specific firmware versions.

3

How can I mitigate CVE-2022-45790?

To mitigate CVE-2022-45790, you should implement strong authentication mechanisms and monitor for brute force attempts.

4

What actions should I take if I believe my system is compromised due to CVE-2022-45790?

If you suspect compromise due to CVE-2022-45790, immediately isolate the affected systems and initiate a security incident response.

5

Is there a patch available for CVE-2022-45790?

Yes, firmware updates addressing CVE-2022-45790 are available from Omron and should be applied as soon as possible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203