Rewterz
Rewterz Threat Advisory – CVE-2023-41834 – Apache Flink Stateful Functions HTTP Vulnerability
September 20, 2023
Rewterz
Rewterz Threat Advisory – CVE-2023-5009 – GitLab EE Vulnerability
September 20, 2023

Rewterz Threat Advisory – ICS: Omron Sysmac Studio and CJ/CS/CP Series devices Vulnerabilities

Severity

High

Analysis Summary

CVE-2022-45790 CVSS:9.8

Omron Sysmac CJ/CS/CP Series devices is vulnerable to a brute force attack, caused by improper restriction of excessive authentication attempts by the login service. By using brute force techniques, a remote attacker could exploit this vulnerability to takeover the account of the administrator.

CVE-2022-45793 CVSS:7.8

Omron Sysmac Studio could allow a local authenticated attacker to execute arbitrary code on the system, caused by improper neutralization of user supplied-input. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.

Impact

  • Gain Access
  • Code Execution

Indicators Of Compromise

CVE

  • CVE-2022-45790
  • CVE-2022-45793

Affected Vendors

Omron

Affected Products

  • Omron CJ2H-CPU 1.4
  • Omron Smart Security Manager 1.5
  • Omron Smart Security Manager 1.30
  • Omron Smart Security Manager 1.4
  • Omron Sysmac Studio 1.54

Remediation

Refer to CISA-CERT Advisory for the patch, upgrade, or suggested workaround information.

Omron CJ/CS/CP Series

Omron Engineering Software