CVE-2023-27396

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jun 19, 2023
Updated: Dec 24, 2024
CWE ID 306

Summary

CVE-2023-27396 affects multiple OMRON products implementing the FINS (Factory Interface Network Service) protocol. The vulnerabilities include plaintext communication and lack of authentication, making it possible for attackers to intercept and inject FINS messages. This can lead to execution of arbitrary commands or retrieval of system information on the affected devices. Affected products include SYSMAC CS-, CJ-, CP-, NJ-, NX1P- and NX102-series CPU Units, as well as SYSMAC NX7 Database Connection CPU Units running version 1.16 or later. These issues pose a significant risk to FA (Factory Automation) networks using OMRON products, necessitating immediate attention and appropriate mitigation measures.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Sysmac NJ

Affected Vendors

  • Omron Foundation Inc.