Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-38744

EPSS 0.30% · P53
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-38744

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Denial-of-service (DoS) vulnerability due to improper validation of specified type of input issue exists in the built-in EtherNet/IP port of the CJ Series CJ2 CPU unit and the communication function of the CS/CJ Series EtherNet/IP unit. If an affected product receives a packet which is specially crafted by a remote unauthenticated attacker, the unit of the affected product may fall into a denial-of-service (DoS) condition. Affected products/versions are as follows: CJ2M CPU Unit CJ2M-CPU3[] Unit version of the built-in EtherNet/IP section Ver. 2.18 and earlier, CJ2H CPU Unit CJ2H-CPU6[]-EIP Unit version of the built-in EtherNet/IP section Ver. 3.04 and earlier, CS/CJ Series EtherNet/IP Unit CS1W-EIP21 V3.04 and earlier, and CS/CJ Series EtherNet/IP Unit CJ1W-EIP21 V3.04 and earlier.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Omron CJ Series 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Omron CJ series是日本欧姆龙(Omron)公司的一系列小型可编程控制器。 Omron CJ Series CJ2 CPU 单元和 CS/CJ Series EtherNet/IP 单元存在安全漏洞,该漏洞源于对指定类型的输入缺乏适当的验证。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
OMRON CorporationCJ2M CPU Unit CJ2M-CPU3[] Unit version of the built-in EtherNet/IP section Ver. 2.18 and earlier -
OMRON CorporationCJ2H CPU Unit CJ2H-CPU6[]-EIP Unit version of the built-in EtherNet/IP section Ver. 3.04 and earlier -
OMRON CorporationCS/CJ Series EtherNet/IP Unit CS1W-EIP21 V3.04 and earlier -
OMRON CorporationCS/CJ Series EtherNet/IP Unit CJ1W-EIP21 V3.04 and earlier -

II. Public POCs for CVE-2023-38744

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-38744

登录查看更多情报信息。

Same Patch Batch · OMRON Corporation · 2023-08-03 · 7 CVEs total

CVE-2023-38748Omron CX-One 资源管理错误漏洞
CVE-2023-38747Omron CX-One 缓冲区错误漏洞
CVE-2023-38746Omron CX-One 缓冲区错误漏洞
CVE-2023-22317Omron CX-Programmer 资源管理错误漏洞
CVE-2023-22314Omron CX-Programmer 资源管理错误漏洞
CVE-2023-22277Omron CX-Programmer 资源管理错误漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2023-38744

No comments yet


Leave a comment