Controller command execution via unauthenticated FINS messages
Published Jun 19, 2023 · Updated Dec 24, 2024
Authentication bypass in OMRON SYSMAC CPU units allows remote attackers to read data or execute controller commands over FINS. The FINS receiver processes plaintext command codes and parameters without encryption, data-authenticity checks, or sender authentication. Network access to FINS is sufficient; exposed operations include I/O, parameter, and program writes, mode changes, file operations, and forced set or reset.
Summary
What happened
Authentication bypass in OMRON SYSMAC CPU units allows remote attackers to read data or execute controller commands over FINS. The FINS receiver processes plaintext command codes and parameters without encryption, data-authenticity checks, or sender authentication. Network access to FINS is sufficient; exposed operations include I/O, parameter, and program writes, mode changes, file operations, and forced set or reset.
The record
- CVE
- CVE-2023-27396
- Published
- Jun 19, 2023
- Updated
- Dec 24, 2024
- Vendor
- Unknown vendor
- Product
- Unknown product
- Classifications
- CWE-799, CWE-345, CWE-290, CWE-412, CWE-400, CWE-319, CWE-294, CWE-306, T1692.001
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Jun 19, 2023CVE publishedPublication date reported by the CVE source.
- Dec 24, 2024Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
What conditions does exploitation require?
What is affected?
Affected products and versions are unavailable in this record.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo