CVE-2022-45790

HIGH
Published Jan 22, 2024 Modified Nov 21, 2024 CWE-307

Description

The Omron FINS protocol has an authenticated feature to prevent access to memory regions. Authentication is susceptible to bruteforce attack, which may allow an adversary to gain access to protected memory. This access can allow overwrite of values including programmed logic.

Is your site exposed to CVE-2022-45790?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

8.6
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Weakness Type (CWE)

CWE-307 CWE-307

Affected Products

Vendor Product
omron cj1g-cpu45p_firmware
omron cj1g-cpu45p
omron cj1g-cpu45p-gtc_firmware
omron cj1g-cpu45p-gtc
omron cj1g-cpu44p_firmware
omron cj1g-cpu44p
omron cj1g-cpu43p_firmware
omron cj1g-cpu43p
omron cj1g-cpu42p_firmware
omron cj1g-cpu42p
omron cp1e-e_firmware
omron cp1e-e
omron cp1e-n_firmware
omron cp1e-n
omron cj2h-cpu68_firmware
omron cj2h-cpu68
omron cj2h-cpu67_firmware
omron cj2h-cpu67
omron cj2h-cpu66_firmware
omron cj2h-cpu66
omron cj2h-cpu65_firmware
omron cj2h-cpu65
omron cj2h-cpu64_firmware
omron cj2h-cpu64
omron cj2h-cpu68-eip_firmware
omron cj2h-cpu68-eip
omron cj2h-cpu67-eip_firmware
omron cj2h-cpu67-eip
omron cj2h-cpu66-eip_firmware
omron cj2h-cpu66-eip
omron cj2h-cpu65-eip_firmware
omron cj2h-cpu65-eip
omron cj2h-cpu64-eip_firmware
omron cj2h-cpu64-eip
omron cj2m-cpu35_firmware
omron cj2m-cpu35
omron cj2m-cpu34_firmware
omron cj2m-cpu34
omron cj2m-cpu33_firmware
omron cj2m-cpu33
omron cj2m-cpu32_firmware
omron cj2m-cpu32
omron cj2m-cpu31_firmware
omron cj2m-cpu31
omron cj2m-cpu15_firmware
omron cj2m-cpu15
omron cj2m-cpu14_firmware
omron cj2m-cpu14
omron cj2m-cpu13_firmware
omron cj2m-cpu13
omron cj2m-cpu12_firmware
omron cj2m-cpu12
omron cj2m-cpu11_firmware
omron cj2m-cpu11
omron cj2m-md211_firmware
omron cj2m-md211
omron cj2m-md212_firmware
omron cj2m-md212
omron cs1d-cpu67s_firmware
omron cs1d-cpu67s
omron cs1d-cpu65s_firmware
omron cs1d-cpu65s
omron cs1d-cpu44s_firmware
omron cs1d-cpu44s
omron cs1d-cpu42s_firmware
omron cs1d-cpu42s
omron cs1d-cpu65p_firmware
omron cs1d-cpu65p
omron cs1d-cpu67p_firmware
omron cs1d-cpu67p
omron cs1d-cpu67h_firmware
omron cs1d-cpu67h
omron cs1d-cpu65h_firmware
omron cs1d-cpu65h
omron cs1h-cpu67h_firmware
omron cs1h-cpu67h
omron cs1h-cpu66h_firmware
omron cs1h-cpu66h
omron cs1h-cpu65h_firmware
omron cs1h-cpu65h
omron cs1h-cpu64h_firmware
omron cs1h-cpu64h
omron cs1h-cpu63h_firmware
omron cs1h-cpu63h
omron cs1g-cpu45h_firmware
omron cs1g-cpu45h
omron cs1g-cpu44h_firmware
omron cs1g-cpu44h
omron cs1g-cpu43h_firmware
omron cs1g-cpu43h
omron cs1g-cpu42h_firmware
omron cs1g-cpu42h

References

Frequently Asked Questions

What is CVE-2022-45790? +
The Omron FINS protocol has an authenticated feature to prevent access to memory regions. Authentication is susceptible to bruteforce attack, which may allow an adversary to gain access to protected memory. This access can allow overwrite of values including programmed logic. It has a CVSS v3.1 base score of 8.6 (HIGH).
How severe is CVE-2022-45790? +
CVE-2022-45790 has a CVSS v3.1 score of 8.6 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2022-45790? +
CVE-2022-45790 affects products from omron, specifically: cj1g-cpu42p, cj1g-cpu42p_firmware, cj1g-cpu43p, cj1g-cpu43p_firmware, cj1g-cpu44p, cj1g-cpu44p_firmware, cj1g-cpu45p, cj1g-cpu45p-gtc, cj1g-cpu45p-gtc_firmware, cj1g-cpu45p_firmware, cj2h-cpu64, cj2h-cpu64-eip, cj2h-cpu64-eip_firmware, cj2h-cpu64_firmware, cj2h-cpu65, cj2h-cpu65-eip, cj2h-cpu65-eip_firmware, cj2h-cpu65_firmware, cj2h-cpu66, cj2h-cpu66-eip, cj2h-cpu66-eip_firmware, cj2h-cpu66_firmware, cj2h-cpu67, cj2h-cpu67-eip, cj2h-cpu67-eip_firmware, cj2h-cpu67_firmware, cj2h-cpu68, cj2h-cpu68-eip, cj2h-cpu68-eip_firmware, cj2h-cpu68_firmware, cj2m-cpu11, cj2m-cpu11_firmware, cj2m-cpu12, cj2m-cpu12_firmware, cj2m-cpu13, cj2m-cpu13_firmware, cj2m-cpu14, cj2m-cpu14_firmware, cj2m-cpu15, cj2m-cpu15_firmware, cj2m-cpu31, cj2m-cpu31_firmware, cj2m-cpu32, cj2m-cpu32_firmware, cj2m-cpu33, cj2m-cpu33_firmware, cj2m-cpu34, cj2m-cpu34_firmware, cj2m-cpu35, cj2m-cpu35_firmware, cj2m-md211, cj2m-md211_firmware, cj2m-md212, cj2m-md212_firmware, cp1e-e, cp1e-e_firmware, cp1e-n, cp1e-n_firmware, cs1d-cpu42s, cs1d-cpu42s_firmware, cs1d-cpu44s, cs1d-cpu44s_firmware, cs1d-cpu65h, cs1d-cpu65h_firmware, cs1d-cpu65p, cs1d-cpu65p_firmware, cs1d-cpu65s, cs1d-cpu65s_firmware, cs1d-cpu67h, cs1d-cpu67h_firmware, cs1d-cpu67p, cs1d-cpu67p_firmware, cs1d-cpu67s, cs1d-cpu67s_firmware, cs1g-cpu42h, cs1g-cpu42h_firmware, cs1g-cpu43h, cs1g-cpu43h_firmware, cs1g-cpu44h, cs1g-cpu44h_firmware, cs1g-cpu45h, cs1g-cpu45h_firmware, cs1h-cpu63h, cs1h-cpu63h_firmware, cs1h-cpu64h, cs1h-cpu64h_firmware, cs1h-cpu65h, cs1h-cpu65h_firmware, cs1h-cpu66h, cs1h-cpu66h_firmware, cs1h-cpu67h, cs1h-cpu67h_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2022-45790? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2022-45790 — free, no signup required.