ID

VAR-202304-1903


CVE

CVE-2023-27396


TITLE

FINS  About security issues in the protocol

Trust: 0.8

sources: JVNDB: JVNDB-2023-001534

DESCRIPTION

FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation) networks, and is used in FA networks composed of OMRON products. Multiple OMRON products that implement FINS protocol contain following security issues -- (1)Plaintext communication, and (2)No authentication required. When FINS messages are intercepted, the contents may be retrieved. When arbitrary FINS messages are injected, any commands may be executed on, or the system information may be retrieved from, the affected device. Affected products and versions are as follows: SYSMAC CS-series CPU Units, all versions, SYSMAC CJ-series CPU Units, all versions, SYSMAC CP-series CPU Units, all versions, SYSMAC NJ-series CPU Units, all versions, SYSMAC NX1P-series CPU Units, all versions, SYSMAC NX102-series CPU Units, all versions, and SYSMAC NX7 Database Connection CPU Units (Ver.1.16 or later). FINS The protocol is manufactured by Omron PLC or PC software, etc. FA network or FA This is a communication protocol that controls the control system using the command/response method. Supported by model FINS The commands are different. * I/O Read memory area / write in * Read parameter area / write in * Read program area / write in * Operation mode change * Read device configuration * CPU Read unit status * Access to time information * Read message / lift * Acquisition and release of access rights * Reading of error history, etc. * File operation * forced set / reset FINS The command message is " FINS header"" FINS It consists of three parts: command code and parameter. FINS Control device that received the command message / The software FINS Executes the processing corresponding to the command code and returns the processing result to FINS as a response message FINS Reply to the sender in the header. for that reason FINS Features such as message encryption, verification, and authentication are not defined. FINS The following problems have been pointed out against the protocol. 1. Plaintext communication FINS The protocol does not define encrypted communication. on the communication path FINS Since messages are sent and received in plain text, it is possible to easily read the contents by intercepting them. again, FINS No functionality is defined to detect message tampering. * Plaintext communication of sensitive information ( CWE-319 ) * Inadequate validation of data reliability ( CWE-345 ) 2. Therefore, it is not possible to identify an attack from a malicious communication partner. * Authentication evasion by spoofing (CWE-290) It was * Capture-replay Authentication evasion by attack (CWE-294) It was * Lack of authentication for critical features (CWE-306) It was * Inadequate validation of data reliability ( CWE-345 ) * Service operation interruption (DoS) Vulnerability (CWE-400) It was * Inadequate restrictions on external operation (CWE-412) It was * Inappropriate limits on interaction frequency (CWE-799) This document is owned by Omron and JPCERT/CC co-authored byFINS If a message is intercepted, its contents can be read

Trust: 1.71

sources: NVD: CVE-2023-27396 // JVNDB: JVNDB-2023-001534 // VULMON: CVE-2023-27396

AFFECTED PRODUCTS

vendor:omronmodel:cp1w-cn811scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n14dt1-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n30dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-e30dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-ext01scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n14dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj501-4310scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n40dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cs1w-drm21-v1scope:eqversion:*

Trust: 1.0

vendor:omronmodel:cj2m-cpu33scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n60sdr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-ts101scope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj501-r420scope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj501-r520scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-n60dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n20dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-da021scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cj2m-cpu12scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-8et1scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-mad42scope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj501-1420scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2w-cifd2scope:eqversion: -

Trust: 1.0

vendor:omronmodel:nx1p2-1140dtscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cj2h-cpu66-eipscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-em40dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-el20dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cj2m-cpu31scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-srt21scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-n14dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n30s1dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:nx701-1620scope:gteversion:1.16

Trust: 1.0

vendor:omronmodel:cj2m-cpu11scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-e10dt-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-l10dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-s60dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-ts002scope:eqversion: -

Trust: 1.0

vendor:omronmodel:nx102-1100scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n60dt-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-l20dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-ts102scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-e60sdr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1h-x40dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-s30dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-m60dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n30sdr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cj2h-cpu68-eipscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-s30dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cj2m-md211scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cj2h-cpu65-eipscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n30s1dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj101-9020scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-e10dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-dab21vscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n40dr-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n30dt1-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-n30dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-l14dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj301-1200scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1h-y20dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-em40dr-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:nx1p2-1040dtscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-e40dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cj2h-cpu64-eipscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-n20dt-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cj2h-cpu68scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-m60dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-l10dt-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-40edtscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cj2h-cpu67-eipscope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj501-r300scope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj501-5300scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-e40dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2w-cifd3scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-n20dr-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-32erscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2w-cifd1scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n40sdt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-n14dr-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:nx102-1000scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n30s1dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj501-4300scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-na20dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-n20dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n40dt1-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-s60dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-em30dr-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n30sdt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj101-1020scope:eqversion: -

Trust: 1.0

vendor:omronmodel:nx1p2-9024dt1scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-s40dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-n14dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n30sdt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-16etscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-e10dt1-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cj2h-cpu65scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n20dt-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-16et1scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n20dt1-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj501-1320scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-cif11scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-l10dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-cif41scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n60s1dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1h-xa40dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-m30dt-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n20dr-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-cif12-v1scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-em30dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj101-1000scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cj2m-cpu32scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n60s1dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-ts004scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-m30dr-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-l10dr-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:nx1p2-1040dt1scope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj-pa3001scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-s40dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj501-4400scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cs1w-etn21scope:eqversion:*

Trust: 1.0

vendor:omronmodel:cp1w-dam01scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n60s1dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cj2m-cpu35scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-em40dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-l14dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n14dt-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-n60dt-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-ad042scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n20dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n60sdt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1h-xa40dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj501-1340scope:eqversion: -

Trust: 1.0

vendor:omronmodel:nx102-9000scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cs1w-spu01-v2scope:eqversion:*

Trust: 1.0

vendor:omronmodel:cp1w-40edt1scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n60sdt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1h-x40dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-n14dt-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-ad041scope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj501-r400scope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj501-r320scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-8edscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-el20dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-20edr1scope:eqversion: -

Trust: 1.0

vendor:omronmodel:nx102-1120scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-em30dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-l20dt-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cs1w-nc471scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-l14dr-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-n60dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-e30sdr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:nx701-1720scope:gteversion:1.16

Trust: 1.0

vendor:omronmodel:cp2e-n30dr-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-s30dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-32etscope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj501-1520scope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj501-4500scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-16erscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-e60dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-m60dt-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cj2m-cpu13scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cj2h-cpu67scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-m60dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cs1w-nc271scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-m30dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n14dr-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj501-1500scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-ts003scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-l20dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj-pd3001scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-adb21scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-8etscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-cif01scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-20edtscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cs1w-fln22scope:eqversion:*

Trust: 1.0

vendor:omronmodel:nj501-1300scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-me05mscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-m40dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n40s1dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n40dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj501-r500scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-mad44scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-da041scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-mab221scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n30dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-n60dr-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1h-x40dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-m60dr-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-l14dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:nx102-1020scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n20dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-20edt1scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n60dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n30dr-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-n30dt-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cj2h-cpu64scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-40edrscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-e20dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-32et1scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-m40dr-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-l14dt-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-e10dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:nx1p2-9024dtscope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj501-4320scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-l20dr-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-e10dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-m30dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cs1w-eip21scope:eqversion:*

Trust: 1.0

vendor:omronmodel:cp1l-l20dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cj2m-md212scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n60dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n40dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cj2m-cpu34scope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj101-9000scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-e20dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-e40sdr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-n40dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n30dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-n30dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1h-xa40dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-n20dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-n40dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-e20sdr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-m40dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-e10dr-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n60dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj501-1400scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cs1w-spu02-v2scope:eqversion:*

Trust: 1.0

vendor:omronmodel:cp1l-l10dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-ts001scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-e14sdr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n40dt-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-el20dr-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-na20dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-e14dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-mad11scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-8erscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n40s1dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-e30dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:nx102-1200scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cj2m-cpu15scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-n30dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n60dt1-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cs1w-ncf71scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cj2h-cpu66scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n14dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-na20dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-m40dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n40sdt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n60dr-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:nj301-1100scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-s60dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n40s1dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-s40dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1w-da042scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n30dt-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-n14dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-m40dt-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-n40dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-n60dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n40sdr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1l-m30dt-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:nx102-1220scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cj2m-cpu14scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp1e-n14dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-n20dt1-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:nx102-9020scope:eqversion: -

Trust: 1.0

vendor:omronmodel:cs1w-clkscope:eqversion:*

Trust: 1.0

vendor:omronmodel:cp2e-e14dr-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-n40dr-dscope:eqversion: -

Trust: 1.0

vendor:omronmodel:cp2e-n40dt-ascope:eqversion: -

Trust: 1.0

vendor:omronmodel:nx1p2-1140dt1scope:eqversion: -

Trust: 1.0

vendor:オムロン株式会社model:sysmac nx1p シリーズ cpu ユニットscope: - version: -

Trust: 0.8

vendor:オムロン株式会社model:sysmac nx7 データベース接続 cpu ユニットscope: - version: -

Trust: 0.8

vendor:オムロン株式会社model:sysmac cs シリーズ cpu ユニットscope: - version: -

Trust: 0.8

vendor:オムロン株式会社model:sysmac nj シリーズ cpu ユニットscope: - version: -

Trust: 0.8

vendor:オムロン株式会社model:sysmac cp シリーズ cpu ユニットscope: - version: -

Trust: 0.8

vendor:オムロン株式会社model:sysmac cj シリーズ cpu ユニットscope: - version: -

Trust: 0.8

vendor:オムロン株式会社model:sysmac nx102 シリーズ cpu ユニットscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2023-001534 // NVD: CVE-2023-27396

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2023-27396
value: CRITICAL

Trust: 1.0

NVD: CVE-2023-27396
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-202304-1396
value: CRITICAL

Trust: 0.6

nvd@nist.gov: CVE-2023-27396
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2023-27396
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2023-001534 // CNNVD: CNNVD-202304-1396 // NVD: CVE-2023-27396

PROBLEMTYPE DATA

problemtype:CWE-306

Trust: 1.0

problemtype:Avoid authentication by spoofing (CWE-290) [ others ]

Trust: 0.8

problemtype:Capture-replay authentication evasion by (CWE-294) [ others ]

Trust: 0.8

problemtype: Lack of authentication for critical features (CWE-306) [ others ]

Trust: 0.8

problemtype: Sending important information in clear text (CWE-319) [ others ]

Trust: 0.8

problemtype: Inadequate verification of data reliability (CWE-345) [ others ]

Trust: 0.8

problemtype: Resource exhaustion (CWE-400) [ others ]

Trust: 0.8

problemtype: Inadequate restrictions on external operations (CWE-412) [ others ]

Trust: 0.8

problemtype: Improper control of interaction frequency (CWE-799) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2023-001534 // NVD: CVE-2023-27396

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202304-1396

TYPE

access control error

Trust: 0.6

sources: CNNVD: CNNVD-202304-1396

PATCH

title:Implemented in multiple Omron products  FINS  Known Issues in Protocolurl:https://www.fa.omron.co.jp/product/vulnerability/OMSR-2023-003_ja.pdf

Trust: 0.8

title:Omron SYSMAC CS/CJ/CP Series Fixes for access control error vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=244012

Trust: 0.6

sources: JVNDB: JVNDB-2023-001534 // CNNVD: CNNVD-202304-1396

EXTERNAL IDS

db:NVDid:CVE-2023-27396

Trust: 3.3

db:ICS CERTid:ICSA-20-063-03

Trust: 1.7

db:ICS CERTid:ICSA-22-179-02

Trust: 1.7

db:ICS CERTid:ICSA-19-346-02

Trust: 1.7

db:JVNDBid:JVNDB-2023-001534

Trust: 1.4

db:JVNid:JVNVU91952379

Trust: 0.8

db:JVNid:JVNVU91000130

Trust: 0.8

db:JVNid:JVNVU97111518

Trust: 0.8

db:CNNVDid:CNNVD-202304-1396

Trust: 0.6

db:VULMONid:CVE-2023-27396

Trust: 0.1

sources: VULMON: CVE-2023-27396 // JVNDB: JVNDB-2023-001534 // CNNVD: CNNVD-202304-1396 // NVD: CVE-2023-27396

REFERENCES

url:https://jvn.jp/ta/jvnta91513661/

Trust: 2.5

url:https://www.fa.omron.co.jp/product/vulnerability/omsr-2023-003_ja.pdf

Trust: 1.7

url:https://www.us-cert.gov/ics/advisories/icsa-19-346-02

Trust: 1.7

url:https://jvn.jp/en/ta/jvnta91513661/

Trust: 1.7

url:https://www.ia.omron.com/product/vulnerability/omsr-2023-003_en.pdf

Trust: 1.7

url:https://www.us-cert.gov/ics/advisories/icsa-20-063-03

Trust: 1.7

url:https://www.cisa.gov/uscert/ics/advisories/icsa-22-179-02

Trust: 1.7

url:https://jvn.jp/vu/jvnvu91000130/

Trust: 0.8

url:https://jvn.jp/vu/jvnvu91952379/

Trust: 0.8

url:https://jvn.jp/vu/jvnvu97111518/

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2023-27396

Trust: 0.8

url:https://cxsecurity.com/cveshow/cve-2023-27396/

Trust: 0.6

url:https://jvndb.jvn.jp/en/contents/2023/jvndb-2023-001534.html

Trust: 0.6

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2023-27396 // JVNDB: JVNDB-2023-001534 // CNNVD: CNNVD-202304-1396 // NVD: CVE-2023-27396

SOURCES

db:VULMONid:CVE-2023-27396
db:JVNDBid:JVNDB-2023-001534
db:CNNVDid:CNNVD-202304-1396
db:NVDid:CVE-2023-27396

LAST UPDATE DATE

2024-08-14T12:30:47.541000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2023-27396date:2023-06-20T00:00:00
db:JVNDBid:JVNDB-2023-001534date:2024-05-23T08:30:00
db:CNNVDid:CNNVD-202304-1396date:2023-07-03T00:00:00
db:NVDid:CVE-2023-27396date:2023-06-30T17:08:06.930

SOURCES RELEASE DATE

db:VULMONid:CVE-2023-27396date:2023-06-19T00:00:00
db:JVNDBid:JVNDB-2023-001534date:2023-04-18T00:00:00
db:CNNVDid:CNNVD-202304-1396date:2023-04-17T00:00:00
db:NVDid:CVE-2023-27396date:2023-06-19T05:15:09.187