CVE-2023-0811
📛 CVE Title
CVE-2023-0811
Description
Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an adversary issues a PROGRAM AREA WRITE command to a specific memory region, they could overwrite the password. This may lead to disabling UM protections or setting a non-ASCII password (non-keyboard characters) and preventing an engineer from viewing or modifying the user program.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- icscert
- CVSS severity
- CRITICAL
- CVSS score
- 9.1 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H- Effective score
- 9.1 / 10 CRITICAL source: CNA overview
- CWE(s)
-
CWE-284 - Reserved
- 2023-02-13
- Published
- 2023-03-16 18:41 UTC
- Last updated
- 2025-01-16 22:42 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/0xxx/CVE-2023-0811.json
- Linked Threat
- CVE-2023-0811 — CVE-2023-0811
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2023-03-16 18:15:11 UTC
- NVD last modified
- 2026-06-17 05:26:21 UTC
- NVD CVSS v3.1
- 9.1 / 10 CRITICAL source: ics-cert@hq.dhs.gov
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H- Exploitability subscore
- 3.9 / 10
- Impact subscore
- 5.2 / 10
- EPSS score
- 0.0062 (probability of exploitation in next 30 days)
- EPSS percentile
- 46.20% vs all CVEs — higher = more likely to be exploited, as of 2026-07-29
NVD / KEV / EPSS data refreshed 2026-07-30 05:51 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2023-12816 - Assigner
- icscert
- Published
- Mar 16, 2023, 5:41:25 PM
- Updated
- Jan 16, 2025, 9:42:32 PM
- EUVD base score (CVSS 3.1)
-
9.1 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H - EUVD-reported EPSS
- 0.3100
- Vendors
- Omron
- Products
-
CJ1M SYSMAC CJ-series (All versions)CJ1M SYSMAC CP-series (All versions)CJ1M SYSMAC CS-series (All versions)CJ1M SYSMAC CS-series (All versions)
- Aliases
-
GHSA-xmm9-hrfr-pphf
ENISA description: Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an adversary issues a PROGRAM AREA WRITE command to a specific memory region, they could overwrite the password. This may lead to disabling UM protections or setting a non-ASCII password (non-keyboard characters) and preventing an engineer from viewing or modifying the user program.
Affected products (23)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Omron | CJ1M SYSMAC CJ-series |
All versions (affected)
|
— |
| Omron | CJ1M SYSMAC CJ-series |
All versions (affected)
|
— |
| Omron | CJ1M SYSMAC CJ-series |
All versions (affected)
|
— |
| Omron | CJ1M SYSMAC CJ-series |
All versions (affected)
|
— |
| Omron | CJ1M SYSMAC CS-series |
All versions (affected)
|
— |
| Omron | CJ1M SYSMAC CS-series |
All versions (affected)
|
— |
| Omron | CJ1M SYSMAC CS-series |
All versions (affected)
|
— |
| Omron | CJ1M SYSMAC CS-series |
All versions (affected)
|
— |
| Omron | CJ1M SYSMAC CS-series |
All versions (affected)
|
— |
| Omron | CJ1M SYSMAC CS-series |
All versions (affected)
|
— |
| Omron | CJ1M SYSMAC CS-series |
All versions (affected)
|
— |
| Omron | CJ1M SYSMAC CP-series |
All versions (affected)
|
— |
| Omron | CJ1M SYSMAC CP-series |
All versions (affected)
|
— |
| Omron | CJ1M SYSMAC CP-series |
All versions (affected)
|
— |
| Omron | CJ1M SYSMAC CP-series |
All versions (affected)
|
— |
| Omron | CJ1M SYSMAC CP-series |
All versions (affected)
|
— |
| Omron | CJ1M SYSMAC CP-series |
All versions (affected)
|
— |
| Omron | CJ1M SYSMAC CP-series |
All versions (affected)
|
— |
| Omron | CJ1M SYSMAC CP-series |
All versions (affected)
|
— |
| Omron | CJ1M SYSMAC CP-series |
All versions (affected)
|
— |
| Omron | CJ1M SYSMAC CP-series |
All versions (affected)
|
— |
| Omron | CJ1M SYSMAC CP-series |
All versions (affected)
|
— |
| Omron | CJ1M SYSMAC CP-series |
All versions (affected)
|
— |
Affected products — CPE 2.3 (256) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:o:omron:sysmac_cj2h-cpu64_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cj2h-cpu64:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cj2h-cpu64-eip_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cj2h-cpu64-eip:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cj2h-cpu65_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cj2h-cpu65:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cj2h-cpu65-eip_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cj2h-cpu65-eip:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cj2h-cpu66_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cj2h-cpu66:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cj2h-cpu66-eip_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cj2h-cpu66-eip:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cj2h-cpu67_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cj2h-cpu67:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cj2h-cpu67-eip_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cj2h-cpu67-eip:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cj2h-cpu68_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cj2h-cpu68:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cj2h-cpu68-eip_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cj2h-cpu68-eip:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cj2m-cpu11_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cj2m-cpu11:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cj2m-cpu12_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cj2m-cpu12:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cj2m-cpu13_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cj2m-cpu13:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cj2m-cpu14_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cj2m-cpu14:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cj2m-cpu15_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cj2m-cpu15:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cj2m-cpu31_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cj2m-cpu31:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cj2m-cpu32_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cj2m-cpu32:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cj2m-cpu33_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cj2m-cpu33:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cj2m-cpu34_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cj2m-cpu34:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cj2m-cpu35_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cj2m-cpu35:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1e-e10dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1e-e10dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1e-e10dr-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1e-e10dr-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1e-e10dt-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1e-e10dt-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1e-e10dt-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1e-e10dt-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1e-e10dt1-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1e-e10dt1-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1e-e10dt1-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1e-e10dt1-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1e-e14dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1e-e14dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1e-e14sdr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1e-e14sdr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1e-e20dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1e-e20dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1e-e20sdr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1e-e20sdr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1e-e30dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1e-e30dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1e-e30sdr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1e-e30sdr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1e-e40dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1e-e40dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1e-e40sdr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1e-e40sdr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1e-e60sdr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1e-e60sdr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1e-na20dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1e-na20dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1e-na20dt-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1e-na20dt-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1e-na20dt1-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1e-na20dt1-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1h-x40dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1h-x40dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1h-x40dt-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1h-x40dt-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1h-x40dt1-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1h-x40dt1-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1h-xa40dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1h-xa40dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1h-xa40dt-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1h-xa40dt-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1h-xa40dt1-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1h-xa40dt1-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1h-y20dt-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1h-y20dt-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-el20dr-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-el20dr-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-em30dr-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-em30dr-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-em30dt-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-em30dt-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-em30dt1-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-em30dt1-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-em40dr-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-em40dr-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-em40dt-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-em40dt-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-em40dt1-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-em40dt1-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-l10dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-l10dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-l10dr-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-l10dr-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-l10dt-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-l10dt-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-l10dt-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-l10dt-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-l10dt1-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-l10dt1-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-l14dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-l14dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-l14dr-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-l14dr-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-l14dt-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-l14dt-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-l14dt-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-l14dt-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-l14dt1-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-l14dt1-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-l20dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-l20dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-l20dr-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-l20dr-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-l20dt-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-l20dt-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-l20dt-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-l20dt-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-l20dt1-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-l20dt1-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-m30dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-m30dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-m30dr-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-m30dr-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-m30dt-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-m30dt-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-m30dt-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-m30dt-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-m30dt1-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-m30dt1-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-m40dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-m40dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-m40dr-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-m40dr-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-m40dt-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-m40dt-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-m40dt-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-m40dt-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-m40dt1-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-m40dt1-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-m60dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-m60dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-m60dr-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-m60dr-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-m60dt-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-m60dt-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-m60dt-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-m60dt-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp1l-m60dt1-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp1l-m60dt1-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-e14dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-e14dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-e20dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-e20dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-e30dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-e30dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-e40dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-e40dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-e60dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-e60dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-n14dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-n14dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-n14dr-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-n14dr-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-n14dt-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-n14dt-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-n14dt-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-n14dt-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-n14dt1-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-n14dt1-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-n20dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-n20dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-n20dr-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-n20dr-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-n20dt-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-n20dt-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-n20dt-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-n20dt-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-n20dt1-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-n20dt1-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-n30dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-n30dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-n30dr-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-n30dr-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-n30dt-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-n30dt-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-n30dt-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-n30dt-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-n30dt1-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-n30dt1-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-n40dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-n40dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-n40dr-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-n40dr-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-n40dt-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-n40dt-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-n40dt-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-n40dt-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-n40dt1-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-n40dt1-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-n60dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-n60dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-n60dr-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-n60dr-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-n60dt-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-n60dt-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-n60dt-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-n60dt-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-n60dt1-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-n60dt1-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-s30dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-s30dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-s30dt-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-s30dt-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-s30dt1-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-s30dt1-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-s40dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-s40dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-s40dt-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-s40dt-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-s40dt1-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-s40dt1-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-s60dr-a_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-s60dr-a:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-s60dt-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-s60dt-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cp2e-s60dt1-d_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cp2e-s60dt1-d:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cs1w-drm21-v1_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cs1w-drm21-v1:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cs1w-eip21_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cs1w-eip21:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cs1w-etn21_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cs1w-etn21:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cs1w-fln22_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cs1w-fln22:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cs1w-nc\[\]71_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cs1w-nc\[\]71:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cs1w-spu01-v2_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cs1w-spu01-v2:-:*:*:*:*:*:*:*cpe:2.3:o:omron:sysmac_cs1w-spu02-v2_firmware:-:*:*:*:*:*:*:*cpe:2.3:h:omron:sysmac_cs1w-spu02-v2:-:*:*:*:*:*:*:*
Vendor references (2)
References embedded in the original CVE record by the assigning CNA.
MITRE references (2) cveawg.mitre.org
Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (4)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-073-01 ics-cert@hq.dhs.gov Third Party AdvisoryUS Government Resource
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-073-01 af854a3a-2127-422b-91ae-364da2661108 Third Party AdvisoryUS Government Resource
- https://www.ia.omron.com/product/vulnerability/OMSR-2023-001_en.pdf ics-cert@hq.dhs.gov MitigationVendor Advisory
- https://www.ia.omron.com/product/vulnerability/OMSR-2023-001_en.pdf af854a3a-2127-422b-91ae-364da2661108 MitigationVendor Advisory
Remediations (16)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:msrc.microsoft.com
The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.
2026-06-02 07:50 UTC -
web:cyberpress.org
Microsoft has rolled out a new cumulative update, KB5089573, for Windows 11 versions 25H2 and 24H2, directly addressing the frustrating installation failures that plagued users during May's Patch Tuesday cycle.
2026-06-02 07:50 UTC -
web:nvd.nist.gov
Vulnerabilities All vulnerabilities in the NVD have been assigned a CVE identifier and thus, abide by the definition below. CVE defines a vulnerability as: "A weakness in the computational logic (e.g., code) found in software and hardware components that, when exploited, results in a negative impact to confidentiality, integrity, or availability. Mitigation of the vulnerabilities in this ...
2026-06-02 07:50 UTC -
web:www.oracle.com
Map of CVE to Advisory/Alert The following table, updated to include the May 28, 2026 Critical Security Patch Update, maps CVEs to specific Critical Patch Update Advisories, Critical Security Patch Update Advisories and Security Alerts for CVEs greater than CVE -2021-0000.
2026-06-02 07:50 UTC -
web:www.rapid7.com
Patch management is the process of distributing and applying updates to software. These patches are often necessary to correct errors (also referred to as "vulnerabilities" or "bugs") in the software.
2026-06-02 07:50 UTC -
web:access.redhat.com
Learn about our open source products, services, and company. You are here
2026-06-02 07:50 UTC -
web:www.bleepingcomputer.com
CISA has ordered U.S. federal agencies to patch a Microsoft Defender privilege escalation flaw (dubbed BlueHammer) that has been exploited in zero-day attacks.
2026-05-22 05:36 UTC -
web:www.cve.org
At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures
2026-05-22 05:36 UTC -
web:www.manageengine.com
Patch Manager Plus, an all-around patching solution, offers automated patch deployment for Windows, macOS, and Linux endpoints. Try ManageEngine's Enterprise patch management software for free!
2026-05-22 05:36 UTC -
web:www.oracle.com
This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.
2026-05-22 05:36 UTC -
web:www.windowslatest.com
Microsoft has confirmed a major Remote Code Execution vulnerability in the modern Notepad app on Windows 11, and the fix is now rolling out as part of the February 2026 Patch Tuesday update. The ...
2026-05-22 05:36 UTC -
web:attack.mitre.org
This mitigation can be implemented through the following measures: Regular Operating System Updates Implementation: Apply the latest Windows security updates monthly using WSUS (Windows Server Update Services) or a similar patch management solution. Configure systems to check for updates automatically and schedule reboots during maintenance ...
2026-05-22 05:36 UTC -
web:cyberpress.org
Three critical vulnerabilities have been disclosed in n8n, the popular open-source workflow automation platform, any one of which could allow an authenticated attacker to achieve remote code execution (RCE) or read arbitrary files from the host server.
2026-05-22 05:36 UTC -
web:nvd.nist.gov
The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics. For ...
2026-05-22 05:36 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 05:36 UTC -
web:windowsreport.com
It's that time of the month again: Microsoft has rolled out its Patch Tuesday updates for Windows 11 versions 23H2, 22H2, and 21H2. Windows 11 23H2 and 22H2 users will see their systems updated through KB5041585, while those on 21H2 will receive KB5041592.
2026-05-22 05:36 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2023-0811.json.
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T05:24:34.505Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-073-01"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.ia.omron.com/product/vulnerability/OMSR-2023-001_en.pdf"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-0811",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-01-16T20:56:16.921497Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-01-16T21:42:32.824Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "CJ2H-CPU6 \u25a1 -EIP",
"product": "CJ1M SYSMAC CJ-series",
"vendor": "Omron ",
"versions": [
{
"status": "affected",
"version": "All versions "
}
]
},
{
"defaultStatus": "unaffected",
"packageName": "CJ2H-CPU6 \u25a1",
"product": "CJ1M SYSMAC CJ-series",
"vendor": "Omron",
"versions": [
{
"status": "affected",
"version": "All versions "
}
]
},
{
"defaultStatus": "unaffected",
"packageName": "CJ2M-CPU \u25a1 \u25a1",
"product": "CJ1M SYSMAC CJ-series",
"vendor": "Omron",
"versions": [
{
"status": "affected",
"version": "All versions "
}
]
},
{
"defaultStatus": "unaffected",
"packageName": "CJ1G-CPU \u25a1 \u25a1 P",
"product": "CJ1M SYSMAC CJ-series",
"vendor": "Omron",
"versions": [
{
"status": "affected",
"version": "All versions "
}
]
},
{
"defaultStatus": "unaffected",
"packageName": "CS1H-CPU \u25a1 \u25a1 H",
"product": "CJ1M SYSMAC CS-series ",
"vendor": "Omron ",
"versions": [
{
"status": "affected",
"version": "All versions "
}
]
},
{
"defaultStatus": "unaffected",
"packageName": "CS1G-CPU \u25a1 \u25a1 H",
"product": "CJ1M SYSMAC CS-series ",
"vendor": "Omron ",
"versions": [
{
"status": "affected",
"version": "All versions "
}
]
},
{
"defaultStatus": "unaffected",
"packageName": "CS1D-CPU \u25a1 \u25a1 HA",
"product": "CJ1M SYSMAC CS-series ",
"vendor": "Omron ",
"versions": [
{
"status": "affected",
"version": "All versions "
}
]
},
{
"defaultStatus": "unaffected",
"packageName": "CS1D-CPU \u25a1 \u25a1 H",
"product": "CJ1M SYSMAC CS-series ",
"vendor": "Omron ",
"versions": [
{
"status": "affected",
"version": "All versions "
}
]
},
{
"defaultStatus": "unaffected",
"packageName": "CS1D-CPU \u25a1 \u25a1 SA",
"product": "CJ1M SYSMAC CS-series ",
"vendor": "Omron",
"versions": [
{
"status": "affected",
"version": "All versions "
}
]
},
{
"defaultStatus": "unaffected",
"packageName": "CS1D-CPU \u25a1 \u25a1 S",
"product": "CJ1M SYSMAC CS-series ",
"vendor": "Omron ",
"versions": [
{
"status": "affected",
"version": "All versions "
}
]
},
{
"defaultStatus": "unaffected",
"packageName": "CS1D-CPU \u25a1 \u25a1 P",
"product": "CJ1M SYSMAC CS-series ",
"vendor": "Omron ",
"versions": [
{
"status": "affected",
"version": "All versions "
}
]
},
{
"defaultStatus": "unaffected",
"packageName": "CP2E-E \u25a1 \u25a1 D \u25a1 - \u25a1",
"product": "CJ1M SYSMAC CP-series",
"vendor": "Omron",
"versions": [
{
"status": "affected",
"version": "All versions "
}
]
},
{
"defaultStatus": "unaffected",
"packageName": "CP2E-S \u25a1 \u25a1 D \u25a1- \u25a1",
"product": "CJ1M SYSMAC CP-series",
"vendor": "Omron",
"versions": [
{
"status": "affected",
"version": "All versions "
}
]
},
{
"defaultStatus": "unaffected",
"packageName": "CP2E-N \u25a1 \u25a1 D \u25a1 - \u25a1",
"product": "CJ1M SYSMAC CP-series",
"vendor": "Omron",
"versions": [
{
"status": "affected",
"version": "All versions "
}
]
},
{
"defaultStatus": "unaffected",
"packageName": "CP1H-X40D \u25a1 - \u25a1",
"product": "CJ1M SYSMAC CP-series",
"vendor": "Omron",
"versions": [
{
"status": "affected",
"version": "All versions "
}
]
},
{
"defaultStatus": "unaffected",
"packageName": "CP1H-XA40D \u25a1 - \u25a1",
"product": "CJ1M SYSMAC CP-series",
"vendor": "Omron",
"versions": [
{
"status": "affected",
"version": "All versions "
}
]
},
{
"defaultStatus": "unaffected",
"packageName": "CP1H-Y20DT-D",
"product": "CJ1M SYSMAC CP-series",
"vendor": "Omron",
"versions": [
{
"status": "affected",
"version": "All versions "
}
]
},
{
"defaultStatus": "unaffected",
"packageName": "CP1L-EL20D \u25a1 - \u25a1",
"product": "CJ1M SYSMAC CP-series",
"vendor": "Omron",
"versions": [
{
"status": "affected",
"version": "All versions "
}
]
},
{
"defaultStatus": "unaffected",
"packageName": "CP1L-EM \u25a1 \u25a1 D \u25a1 - \u25a1",
"product": "CJ1M SYSMAC CP-series",
"vendor": "Omron",
"versions": [
{
"status": "affected",
"version": "All versions "
}
]
},
{
"defaultStatus": "unaffected",
"packageName": "CP1L-L \u25a1 \u25a1 D \u25a1- \u25a1",
"product": "CJ1M SYSMAC CP-series",
"vendor": "Omron",
"versions": [
{
"status": "affected",
"version": "All versions "
}
]
},
{
"defaultStatus": "unaffected",
"packageName": "CP1L-M \u25a1 \u25a1 D \u25a1 - \u25a1",
"product": "CJ1M SYSMAC CP-series",
"vendor": "Omron",
"versions": [
{
"status": "affected",
"version": "All versions "
}
]
},
{
"defaultStatus": "unaffected",
"packageName": "CP1E-E \u25a1 \u25a1 D \u25a1 - \u25a1",
"product": "CJ1M SYSMAC CP-series",
"vendor": "Omron",
"versions": [
{
"status": "affected",
"version": "All versions "
}
]
},
{
"defaultStatus": "unaffected",
"packageName": "CP1E-NA \u25a1 \u25a1 D \u25a1 - \u25a1",
"product": "CJ1M SYSMAC CP-series",
"vendor": "Omron",
"versions": [
{
"status": "affected",
"version": "All versions "
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"user": "00000000-0000-4000-9000-000000000000",
"value": "Sam Hanson of Dragos reported these vulnerabilities to CISA. "
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\n\n<span style=\"background-color: rgb(255, 255, 255);\">Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an adversary issues a PROGRAM AREA WRITE command to a specific memory region, they could overwrite the password. This may lead to disabling UM protections or setting a non-ASCII password (non-keyboard characters) and preventing an engineer from viewing or modifying the user program. </span>\n\n"
}
],
"value": "\nOmron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an adversary issues a PROGRAM AREA WRITE command to a specific memory region, they could overwrite the password. This may lead to disabling UM protections or setting a non-ASCII password (non-keyboard characters) and preventing an engineer from viewing or modifying the user program. \n\n"
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-284",
"description": "CWE-284 Improper Access Control ",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-03-16T17:45:14.919Z",
"orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"shortName": "icscert"
},
"references": [
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-073-01"
},
{
"url": "https://www.ia.omron.com/product/vulnerability/OMSR-2023-001_en.pdf"
}
],
"source": {
"discovery": "UNKNOWN"
},
"workarounds": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\n\n<p>OMRON has released the following countermeasures for users to implement: </p><ul><li>Enable the hardware switch to prohibit writing UM (DIP switch on front panel of the CPU Unit) </li><li>Set UM read protection password and \u201cProhibit from overwriting to a protected program \u201coption. </li></ul><p>If the countermeasures cannot be applied, OMRON recommends that customers take the following mitigation measures: </p><p>Security measures to prevent unauthorized access: </p><ul><li>If the following products and versions are used, the risk of attacks by an attacker via the network can be reduced by taking the following measures. <ul><li>Enable the FINS write protection function. </li><li>Select the Protect by IP Address </li></ul></li><li>Minimize connection of control systems and equipment to open networks, so that untrusted devices will be unable to access them. </li><li>Implement firewalls (by shutting down unused communications ports, limiting communications hosts, limiting access to FINS port (9600)) and isolate them from the IT network. </li><li>Use a virtual private network (VPN) for remote access to control systems and equipment. </li><li>Use strong passwords and change them frequently. </li><li>Install physical controls so that only authorized personnel can access control systems and equipment. </li><li>Scan virus to ensure safety of any USB drives or similar devices before connecting them to systems and devices. </li><li>Enforce multifactor authentication to all devices with remote access to control systems and equipment whenever possible. </li><li>Anti-virus protection <ul><li>Protect any PC with access to the control system against malware and ensure installation and maintenance of up-to-date commercial grade anti-virus software protection. </li></ul></li><li>Data input and output protection <ul><li>Validation processing such as backup and range check to cope with unintentional modification of input/output data to control systems and devices. </li></ul></li><li>Data recovery <ul><li>Periodical data backup and maintenance to prepare for data loss. </li></ul></li></ul><p>For more information, see Omron\u2019s <a target=\"_blank\" rel=\"nofollow\" href=\"https://www.ia.omron.com/product/vulnerability/OMSR-2023-001_en.pdf\">Security Advisory</a>.</p><br>\n\n<br>"
}
],
"value": "\nOMRON has released the following countermeasures for users to implement: \n\n * Enable the hardware switch to prohibit writing UM (DIP switch on front panel of the CPU Unit) \n * Set UM read protection password and \u201cProhibit from overwriting to a protected program \u201coption. \n\n\nIf the countermeasures cannot be applied, OMRON recommends that customers take the following mitigation measures: \n\nSecurity measures to prevent unauthorized access: \n\n * If the following products and versions are used, the risk of attacks by an attacker via the network can be reduced by taking the following measures. * Enable the FINS write protection function. \n * Select the Protect by IP Address \n\n\n\n * Minimize connection of control systems and equipment to open networks, so that untrusted devices will be unable to access them. \u00a0\n * Implement firewalls (by shutting down unused communications ports, limiting communications hosts, limiting access to FINS port (9600)) and isolate them from the IT network. \n * Use a virtual private network (VPN) for remote access to control systems and equipment. \n * Use strong passwords and change them frequently. \n * Install physical controls so that only authorized personnel can access control systems and equipment. \n * Scan virus to ensure safety of any USB drives or similar devices before connecting them to systems and devices. \n * Enforce multifactor authentication to all devices with remote access to control systems and equipment whenever possible. \n * Anti-virus protection * Protect any PC with access to the control system against malware and ensure installation and maintenance of up-to-date commercial grade anti-virus software protection. \n\n\n\n * Data input and output protection * Validation processing such as backup and range check to cope with unintentional modification of input/output data to control systems and devices. \n\n\n\n * Data recovery * Periodical data backup and maintenance to prepare for data loss. \n\n\n\n\n\nFor more information, see Omron\u2019s Security Advisory https://www.ia.omron.com/product/vulnerability/OMSR-2023-001_en.pdf .\n\n\n\n\n\n"
}
],
"x_generator": {
"engine": "Vulnogram 0.1.0-dev"
}
}
},
"cveMetadata": {
"assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"assignerShortName": "icscert",
"cveId": "CVE-2023-0811",
"datePublished": "2023-03-16T17:41:25.525Z",
"dateReserved": "2023-02-13T15:41:55.590Z",
"dateUpdated": "2025-01-16T21:42:32.824Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}