Vulnerability Description
An attacker with network access to the affected PLC (CJ-series and CS-series PLCs, all versions) may use a network protocol to read and write files on the PLC internal memory and memory card.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Omron | Sysmac Cj2H-Cpu64-Eip Firmware | - |
| Omron | Sysmac Cj2H-Cpu64-Eip | - |
| Omron | Sysmac Cj2H-Cpu64 Firmware | - |
| Omron | Sysmac Cj2H-Cpu64 | - |
| Omron | Sysmac Cj2H-Cpu65-Eip Firmware | - |
| Omron | Sysmac Cj2H-Cpu65-Eip | - |
| Omron | Sysmac Cj2H-Cpu65 Firmware | - |
| Omron | Sysmac Cj2H-Cpu65 | - |
| Omron | Sysmac Cj2H-Cpu66-Eip Firmware | - |
| Omron | Sysmac Cj2H-Cpu66-Eip | - |
| Omron | Sysmac Cj2H-Cpu66 Firmware | - |
| Omron | Sysmac Cj2H-Cpu66 | - |
| Omron | Sysmac Cj2H-Cpu67-Eip Firmware | - |
| Omron | Sysmac Cj2H-Cpu67-Eip | - |
| Omron | Sysmac Cj2H-Cpu67 Firmware | - |
| Omron | Sysmac Cj2H-Cpu67 | - |
| Omron | Sysmac Cj2H-Cpu68-Eip Firmware | - |
| Omron | Sysmac Cj2H-Cpu68-Eip | - |
| Omron | Sysmac Cj2H-Cpu68 Firmware | - |
| Omron | Sysmac Cj2H-Cpu68 | - |
Related Weaknesses (CWE)
References
- https://www.dragos.com/advisory/omron-plc-and-engineering-software-network-and-fThird Party Advisory
- https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2023-002_en.pdfVendor Advisory
- https://www.dragos.com/advisory/omron-plc-and-engineering-software-network-and-fThird Party Advisory
- https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2023-002_en.pdfVendor Advisory
FAQ
What is CVE-2022-45794?
CVE-2022-45794 is a vulnerability with a CVSS score of 8.6 (HIGH). An attacker with network access to the affected PLC (CJ-series and CS-series PLCs, all versions) may use a network protocol to read and write files on the PLC internal memory and memory card.
How severe is CVE-2022-45794?
CVE-2022-45794 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-45794?
Check the references section above for vendor advisories and patch information. Affected products include: Omron Sysmac Cj2H-Cpu64-Eip Firmware, Omron Sysmac Cj2H-Cpu64-Eip, Omron Sysmac Cj2H-Cpu64 Firmware, Omron Sysmac Cj2H-Cpu64, Omron Sysmac Cj2H-Cpu65-Eip Firmware.