CVE-2022-31207

The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic authentication. They utilize the Omron FINS (9600/TCP) protocol for engineering purposes, including downloading projects and control logic to the PLC. This protocol has authentication flaws as reported in FSCT-2022-0057. Control logic is downloaded to PLC volatile memory using the FINS Program Area Read and Program Area Write commands or to non-volatile memory using other commands from where it can be loaded into volatile memory for execution. The logic that is loaded into and executed from the user program area exists in compiled object code form. Upon execution, these object codes are first passed to a dedicated ASIC that determines whether the object code is to be executed by the ASIC or the microprocessor. In the former case, the object code is interpreted by the ASIC whereas in the latter case the object code is passed to the microprocessor for object code interpretation by a ROM interpreter. In the abnormal case where the object code cannot be handled by either, an abnormal condition is triggered and the PLC is halted. The logic that is downloaded to the PLC does not seem to be cryptographically authenticated, thus allowing an attacker to manipulate transmitted object code to the PLC and either execute arbitrary object code commands on the ASIC or on the microprocessor interpreter.
References
Link Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-22-179-02 Third Party Advisory US Government Resource
https://www.forescout.com/blog/ Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:omron:sysmac_cs1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:omron:sysmac_cs1:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:omron:sysmac_cj2m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:omron:sysmac_cj2m:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:omron:sysmac_cj2h_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:omron:sysmac_cj2h:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:omron:sysmac_cp1e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:omron:sysmac_cp1e:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:omron:sysmac_cp1h_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:omron:sysmac_cp1h:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:omron:sysmac_cp1l_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:omron:sysmac_cp1l:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:omron:cp1w-cif41_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:omron:cp1w-cif41:-:*:*:*:*:*:*:*

History

04 Aug 2022, 15:01

Type Values Removed Values Added
References (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-22-179-02 - (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-22-179-02 - Third Party Advisory, US Government Resource
References (MISC) https://www.forescout.com/blog/ - (MISC) https://www.forescout.com/blog/ - Third Party Advisory
CWE CWE-347
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Omron cp1w-cif41
Omron sysmac Cp1e Firmware
Omron
Omron sysmac Cj2m Firmware
Omron sysmac Cp1l
Omron sysmac Cs1 Firmware
Omron sysmac Cp1h
Omron sysmac Cj2h Firmware
Omron sysmac Cp1l Firmware
Omron sysmac Cp1e
Omron cp1w-cif41 Firmware
Omron sysmac Cj2m
Omron sysmac Cp1h Firmware
Omron sysmac Cs1
Omron sysmac Cj2h
CPE cpe:2.3:h:omron:cp1w-cif41:-:*:*:*:*:*:*:*
cpe:2.3:o:omron:cp1w-cif41_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:omron:sysmac_cs1:-:*:*:*:*:*:*:*
cpe:2.3:h:omron:sysmac_cj2h:-:*:*:*:*:*:*:*
cpe:2.3:o:omron:sysmac_cj2h_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:omron:sysmac_cp1e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:omron:sysmac_cp1h_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:omron:sysmac_cp1e:-:*:*:*:*:*:*:*
cpe:2.3:h:omron:sysmac_cp1l:-:*:*:*:*:*:*:*
cpe:2.3:h:omron:sysmac_cp1h:-:*:*:*:*:*:*:*
cpe:2.3:o:omron:sysmac_cj2m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:omron:sysmac_cs1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:omron:sysmac_cj2m:-:*:*:*:*:*:*:*
cpe:2.3:o:omron:sysmac_cp1l_firmware:*:*:*:*:*:*:*:*

26 Jul 2022, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-07-26 22:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-31207

Mitre link : CVE-2022-31207

CVE.ORG link : CVE-2022-31207


JSON object : View

Products Affected

omron

  • sysmac_cj2h_firmware
  • sysmac_cj2h
  • sysmac_cp1e
  • sysmac_cp1h_firmware
  • sysmac_cp1h
  • cp1w-cif41_firmware
  • sysmac_cp1e_firmware
  • sysmac_cj2m_firmware
  • sysmac_cs1
  • sysmac_cp1l_firmware
  • cp1w-cif41
  • sysmac_cp1l
  • sysmac_cs1_firmware
  • sysmac_cj2m
CWE
CWE-347

Improper Verification of Cryptographic Signature