Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xmm9-hrfr-pphf

Опубликовано: 16 мар. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an adversary issues a PROGRAM AREA WRITE command to a specific memory region, they could overwrite the password. This may lead to disabling UM protections or setting a non-ASCII password (non-keyboard characters) and preventing an engineer from viewing or modifying the user program.

Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an adversary issues a PROGRAM AREA WRITE command to a specific memory region, they could overwrite the password. This may lead to disabling UM protections or setting a non-ASCII password (non-keyboard characters) and preventing an engineer from viewing or modifying the user program.

EPSS

Процентиль: 37%
0.00163
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 9.1
nvd
около 3 лет назад

Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an adversary issues a PROGRAM AREA WRITE command to a specific memory region, they could overwrite the password. This may lead to disabling UM protections or setting a non-ASCII password (non-keyboard characters) and preventing an engineer from viewing or modifying the user program.

CVSS3: 9.1
fstec
около 3 лет назад

Уязвимость микропрограммного обеспечения программируемых логических контроллеров SYSMAC серий CS, CJ и CP, позволяющая нарушителю обойти существующие ограничения безопасности и получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 37%
0.00163
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-284