Security Advisory

CVE-2023-0811

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-03-16 17:41:25
Last updated 2025-01-16 21:42:32
Assigner icscert
CVSS score 9.1
State PUBLISHED

Description

Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an adversary issues a PROGRAM AREA WRITE command to a specific memory region, they could overwrite the password. This may lead to disabling UM protections or setting a non-ASCII password (non-keyboard characters) and preventing an engineer from viewing or modifying the user program.