Cleartext Password Vulnerability in Omron PLCs
CVE-2022-31204
7.5HIGH
What is CVE-2022-31204?
The Omron CS, CJ, and CP series PLCs have a vulnerability that permits the use of cleartext passwords within their configuration settings. This issue stems from the UM Protection feature that allows users to set passwords for sensitive engineering tasks, such as uploading and downloading logic and project files. Unfortunately, the commands used to set and clear these passwords are transmitted in cleartext, making them susceptible to interception by malicious actors, thus compromising the security of these critical industrial control systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
