Description


Active debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS protocol being executed without authentication. A remote unauthenticated attacker may read/write in arbitrary area of the device memory, which may lead to overwriting the firmware, causing a denial-of-service (DoS) condition, and/or arbitrary code execution.

Weaknesses



NVD-CWE-Other

134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-489

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.8 · Critical

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2023-01-17T09:15:11.887Z

3 years ago

Last modified

2025-04-04T16:15:47.297Z

11 months ago