ICSA-22-179-02
·
Published 2022-06-28
·
View on CISA ICS-CERT ↗
Omron SYSMAC CS/CJ/CP Series and NJ/NX Series
CVSS 6.5
MEDIUM
Risk Summary
Successful exploitation of these vulnerabilities could cause a denial-of-service condition and allow remote code execution.
Remediations
- For CVE-2022-31204: Omron recommends users implement an extended password protection function in the following product versions: CS1: v.4.1 or later
- For CVE-2022-31204: Omron recommends users implement an extended password protection function in the following product versions: CJ2M: v2.1 or later
- For CVE-2022-31204: Omron recommends users implement an extended password protection function in the following product versions: CJ2H: v1.5 or later
- For CVE-2022-31204: Omron recommends users implement an extended password protection function in the following product versions: CP1E/CP1H: v1.30 or later
- For CVE-2022-31204: Omron recommends users implement an extended password protection function in the following product versions: CP1L: v1.10 or later
- For CVE-2022-31204: Omron recommends users implement an extended password protection function in the following product versions: CX-Programmer: v9.6 or higher
- For CVE-2022-31205: Omron recommends using different passwords between the CP1W-CIF41 Ethernet Option Board and CP1 PLC itself. The Web UI password will not grant access to the PLC.
- For CVE-2022-31207: Omron recommends users of SYSMAC CS/CJ/CP Series to use the PLC protection password and enable protection against unauthorized write access to address. Also, there are hardware DIP switches on the PLC which can prevent unauthorized PLC program changes regardless of password.
- For CVE-2022-31206: Omron intends to publish an update for SYSMAC NJ/NX in July 2022.
Affected Vendors
Omron
Affected Products (8)
Omron
·
CP1W-CIF41
vers:all/*
Omron
·
SYSMAC CJ2H
< 1.5
Omron
·
SYSMAC CJ2M
< 2.1
Omron
·
SYSMAC CP1E/CP1H
< 1.30
Omron
·
SYSMAC CP1L
< 1.10
Omron
·
SYSMAC CS1H/CJ1G
< 4.1
Omron
·
SYSMAC CX-Programmer
< 9.6
Omron
·
SYSMAC NJ/NX Series
< 1.49 (1.29 for NX7)
Affected Sectors
Critical Manufacturing
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more