CVE-2022-45790

critical

Description

The Omron FINS protocol has an authenticated feature to prevent access to memory regions. Authentication is susceptible to bruteforce attack, which may allow an adversary to gain access to protected memory. This access can allow overwrite of values including programmed logic.

References

https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2023-010_en.pdf

https://www.dragos.com/advisory/omron-plc-and-engineering-software-network-and-file-format-access/

https://www.cisa.gov/news-events/ics-advisories/icsa-23-262-05

Details

Source: Mitre, NVD

Published: 2024-01-22

Updated: 2024-01-29

Risk Information

CVSS v2

Base Score: 9.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

Severity: High

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical