An attacker with network access to the affected PLC (CJ-series and CS-series PLCs, all versions) may use a network protocol to read and write files on the PLC internal memory and memory card.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2023-002_en.pdf | vendor advisory |
https://www.dragos.com/advisory/omron-plc-and-engineering-software-network-and-file-format-access/ | third party advisory |