ID

VAR-201605-0618


TITLE

OMRON CP1W-C1F41 Module HTTP Service Denial of Service Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2016-03455

DESCRIPTION

OMRON CP1H-XA40DT-D is a compact PLC produced by Japan's Omron Corporation and is widely used in manufacturing. CP1W-C1F41 is the Ethernet module of CP1H-XA40DT-D PLC. There is a denial of service vulnerability in the HTTP protocol of the CP1W-C1F41 module. After the client establishes a link with port 80 of CP1W-C1F41 and sends an exception string ":" to it (note: there is a space after the colon), it can cause the HTTP service of CP1W-C1F41 to be abnormal and port 80 can no longer be accessed. The PLC needs to be restarted manually before HTTP service can recover

Trust: 0.72

sources: CNVD: CNVD-2016-03455 // IVD: eb198f37-be9d-4da5-bbf2-9007778e35fb

IOT TAXONOMY

category:['ICS', 'Network device']sub_category: -

Trust: 0.6

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: eb198f37-be9d-4da5-bbf2-9007778e35fb // CNVD: CNVD-2016-03455

AFFECTED PRODUCTS

vendor:omronmodel:cp1h-xa40dt-dscope:eqversion:1.2

Trust: 0.8

sources: IVD: eb198f37-be9d-4da5-bbf2-9007778e35fb // CNVD: CNVD-2016-03455

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2016-03455
value: HIGH

Trust: 0.6

IVD: eb198f37-be9d-4da5-bbf2-9007778e35fb
value: HIGH

Trust: 0.2

CNVD: CNVD-2016-03455
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: eb198f37-be9d-4da5-bbf2-9007778e35fb
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: eb198f37-be9d-4da5-bbf2-9007778e35fb // CNVD: CNVD-2016-03455

TYPE

Denial of service

Trust: 0.2

sources: IVD: eb198f37-be9d-4da5-bbf2-9007778e35fb

EXTERNAL IDS

db:CNVDid:CNVD-2016-03455

Trust: 0.8

db:IVDid:EB198F37-BE9D-4DA5-BBF2-9007778E35FB

Trust: 0.2

sources: IVD: eb198f37-be9d-4da5-bbf2-9007778e35fb // CNVD: CNVD-2016-03455

SOURCES

db:IVDid:eb198f37-be9d-4da5-bbf2-9007778e35fb
db:CNVDid:CNVD-2016-03455

LAST UPDATE DATE

2022-05-17T01:43:18.915000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-03455date:2016-12-24T00:00:00

SOURCES RELEASE DATE

db:IVDid:eb198f37-be9d-4da5-bbf2-9007778e35fbdate:2016-05-24T00:00:00
db:CNVDid:CNVD-2016-03455date:2016-06-21T00:00:00