The Omron FINS protocol has an authenticated feature to prevent access to memory regions. Authentication is susceptible to bruteforce attack, which may allow an adversary to gain access to protected memory. This access can allow overwrite of values including programmed logic.
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Link | Tags |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-23-262-05 | third party advisory us government resource |
https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2023-010_en.pdf | vendor advisory |
https://www.dragos.com/advisory/omron-plc-and-engineering-software-network-and-file-format-access/ | third party advisory |