Omron CJ1M unit v4.0 and prior has improper access...
Critical severity
Unreviewed
Published
Mar 16, 2023
to the GitHub Advisory Database
•
Updated Apr 5, 2023
Description
Published by the National Vulnerability Database
Mar 16, 2023
Published to the GitHub Advisory Database
Mar 16, 2023
Last updated
Apr 5, 2023
Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an adversary issues a PROGRAM AREA WRITE command to a specific memory region, they could overwrite the password. This may lead to disabling UM protections or setting a non-ASCII password (non-keyboard characters) and preventing an engineer from viewing or modifying the user program.
References