CVE-2023-27396

CRITICALCVSS 9.8/10EPSS 1.39%

Last modified

CVE-2023-27396 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation) networks, and is used in FA networks composed of OMRON products. Multiple OMRON products that implement FINS protocol contain following security issues -- (1)Plaintext communication, and (2)No authentication required. EPSS estimates a 1.39% chance of exploitation in the next 30 days.

Description

FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation) networks, and is used in FA networks composed of OMRON products. Multiple OMRON products that implement FINS protocol contain following security issues -- (1)Plaintext communication, and (2)No authentication required. When FINS messages are intercepted, the contents may be retrieved. When arbitrary FINS messages are injected, any commands may be executed on, or the system information may be retrieved from, the affected device. Affected products and versions are as follows: SYSMAC CS-series CPU Units, all versions, SYSMAC CJ-series CPU Units, all versions, SYSMAC CP-series CPU Units, all versions, SYSMAC NJ-series CPU Units, all versions, SYSMAC NX1P-series CPU Units, all versions, SYSMAC NX102-series CPU Units, all versions, and SYSMAC NX7 Database Connection CPU Units (Ver.1.16 or later)

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
1.39%

68.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
OmronCs1w-Eip21 FirmwareAll versions
OmronCs1w-Spu01-V2 FirmwareAll versions
OmronCs1w-Spu02-V2 FirmwareAll versions
OmronCs1w-Etn21 FirmwareAll versions
OmronCs1w-Clk FirmwareAll versions
OmronCs1w-Fln22 FirmwareAll versions
OmronCs1w-Drm21-V1 FirmwareAll versions
OmronCs1w-Nc271 FirmwareAll versions
OmronCs1w-Nc471 FirmwareAll versions
OmronCs1w-Ncf71 FirmwareAll versions
OmronCj2m-Cpu35 FirmwareAll versions
OmronCj2m-Cpu34 FirmwareAll versions
OmronCj2m-Cpu33 FirmwareAll versions
OmronCj2m-Cpu32 FirmwareAll versions
OmronCj2m-Cpu31 FirmwareAll versions
OmronCj2m-Cpu15 FirmwareAll versions
OmronCj2m-Cpu14 FirmwareAll versions
OmronCj2m-Cpu13 FirmwareAll versions
OmronCj2m-Cpu12 FirmwareAll versions
OmronCj2m-Cpu11 FirmwareAll versions
OmronCp1w-Cif01 FirmwareAll versions
OmronCp1w-Cif11 FirmwareAll versions
OmronCp1w-Cif12-V1 FirmwareAll versions
OmronCj2m-Md211 FirmwareAll versions
OmronCj2m-Md212 FirmwareAll versions
OmronCj2h-Cpu68-Eip FirmwareAll versions
OmronCj2h-Cpu67-Eip FirmwareAll versions
OmronCj2h-Cpu66-Eip FirmwareAll versions
OmronCj2h-Cpu65-Eip FirmwareAll versions
OmronCj2h-Cpu64-Eip FirmwareAll versions
OmronCj2h-Cpu68 FirmwareAll versions
OmronCj2h-Cpu67 FirmwareAll versions
OmronCj2h-Cpu66 FirmwareAll versions
OmronCj2h-Cpu65 FirmwareAll versions
OmronCj2h-Cpu64 FirmwareAll versions
OmronCp2e-N14dr-A FirmwareAll versions
OmronCp2e-N14dt-A FirmwareAll versions
OmronCp2e-N14dr-D FirmwareAll versions
OmronCp2e-N14dt-D FirmwareAll versions
OmronCp2e-N14dt1-D FirmwareAll versions
OmronCp2e-N20dr-A FirmwareAll versions
OmronCp2e-N20dt-A FirmwareAll versions
OmronCp2e-N20dr-D FirmwareAll versions
OmronCp2e-N20dt-D FirmwareAll versions
OmronCp2e-N20dt1-D FirmwareAll versions
OmronCp2e-N30dr-A FirmwareAll versions
OmronCp2e-N30dt-A FirmwareAll versions
OmronCp2e-N30dr-D FirmwareAll versions
OmronCp2e-N30dt-D FirmwareAll versions
OmronCp2e-N30dt1-D FirmwareAll versions

Showing 50 of 271 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-27396?
FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation) networks, and is used in FA networks composed of OMRON products. Multiple OMRON products that implement FINS protocol contain following security issues -- (1)Plaintext communication, and (2)No authentication required. When FINS messages are intercepted, the contents may be retrieved. When arbitrary FINS messages are injected, any commands may be executed on, or the system information may be retrieved from, the affected device. Affected products and versions are as follows: SYSMAC CS-series CPU Units, all versions, SYSMAC CJ-series CPU Units, all versions, SYSMAC CP-series CPU Units, all versions, SYSMAC NJ-series CPU Units, all versions, SYSMAC NX1P-series CPU Units, all versions, SYSMAC NX102-series CPU Units, all versions, and SYSMAC NX7 Database Connection CPU Units (Ver.1.16 or later)
How severe is CVE-2023-27396?
CVE-2023-27396 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 1.39% probability of exploitation in the next 30 days.
How do I fix CVE-2023-27396?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-27396?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST