CVE-2023-22357: Critical severity omron sysmac cp1l-el20dr-d firmware vulnerability
Active debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS protocol being executed without authentication. A remote unauthenticated attacker may read/write in arbitrary area of the device memory, which may lead to overwriting the firmware, causing a denial-of-service (DoS) condition, and/or arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-22357.
What products are affected by CVE-2023-22357 vulnerability?
OMRON CP1L-EL20DR-D all versions are affected by this vulnerability.
What is the severity of CVE-2023-22357?
CVE-2023-22357 has a severity rating of 9.8 (Critical).
How does CVE-2023-22357 impact the device?
CVE-2023-22357 allows remote unauthenticated attackers to read/write in arbitrary memory areas of the affected device, potentially overwriting the firmware.
Is there a fix available for CVE-2023-22357?
At the moment, there is no specific fix available for CVE-2023-22357. Contact the vendor for further information and recommendations.