← Back to home
ICSA-22-242-09  ·  Published 2022-08-30  ·  View on CISA ICS-CERT ↗

Omron CX-Programmer

CVSS 7.8 HIGH

Risk Summary

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code.

CVEs (1)

Remediations

  • Omron CX-Programmer: Update to v9.78
  • Should assistance be needed for the update process, users should contact Omron.
  • Use antivirus protection by protecting any PC with access to the control system against malware and ensure installation and maintenance of up-to-date commercial grade antivirus software protection.
  • Use strong passwords and change them frequently.
  • Install physical controls, allowing only authorized personnel access to control systems and equipment.
  • Perform virus scans to ensure safety of any USB drives or similar devices before connecting to systems and devices.
  • Enforce multifactor authentication on all devices with remote access to control systems and equipment whenever possible.
  • Perform validation processing, such as backup and range checks, to cope with unintentional modification of input/output data to control systems and devices.
  • Perform periodic data backup and maintenance to prepare for data loss.
  • Do not click web links or open attachments in unsolicited email messages.
  • Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.
  • Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.

Affected Vendors

Omron

Affected Products (1)

Omron · Omron CX-Programmer < 9.78

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more