Active debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS protocol being executed without authentication. A remote unauthenticated attacker may read/write in arbitrary area of the device memory, which may lead to overwriting the firmware, causing a denial-of-service (DoS) condition, and/or arbitrary code execution.
                
            References
                    | Link | Resource | 
|---|---|
| https://jvn.jp/en/vu/JVNVU97575890/index.html | Third Party Advisory | 
| https://jvn.jp/en/vu/JVNVU97575890/index.html | Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
            
            
 
  | 
    
History
                    04 Apr 2025, 18:15
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-489 | 
21 Nov 2024, 07:44
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://jvn.jp/en/vu/JVNVU97575890/index.html - Third Party Advisory | 
Information
                Published : 2023-01-17 10:15
Updated : 2025-04-04 18:15
NVD link : CVE-2023-22357
Mitre link : CVE-2023-22357
CVE.ORG link : CVE-2023-22357
JSON object : View
Products Affected
                omron
- cp1l-el20dr-d
 - cp1l-el20dr-d_firmware
 
CWE
                