CVE-2023-22357
About
Active debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS protocol being executed without authentication. A remote unauthenticated attacker may read/write in arbitrary area of the device memory, which may lead to overwriting the firmware, causing a denial-of-service (DoS) condition, and/or arbitrary code execution.
Rainforest analyst review
The OMRON CP1L-EL20DR-D controller contains active debug code that lets a command outside the documented FINS protocol run without any authentication. Over the network, an unauthenticated attacker can read and write arbitrary regions of device memory, which the advisory spells out can mean overwriting firmware, forcing a denial of service, or achieving arbitrary code execution. This is full control of a PLC with no credential required.
This is an OT/ICS device, and the threat model is unforgiving: PLCs govern physical processes, so memory read/write and firmware overwrite translate to real-world disruption, not just data loss. These controllers should never face the internet, yet exposed industrial devices are routinely found by ICS-aware scanning, and unauthenticated, protocol-level access like this is precisely what makes them dangerous when they are reachable.
Our controlling question is exposure and segmentation, not patching, since OT devices are slow and disruptive to update. We would hunt for any CP1L-EL20DR-D reachable from IT or internet networks, verify it sits behind proper ICS segmentation with FINS traffic restricted to trusted engineering hosts, and monitor for anomalous protocol access. For gear like this, cutting reachability is the fix that can actually be applied on operational timelines.
References
Related CVEs
Frequently asked questions
What is CVE-2023-22357?
Active debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS protocol being executed without authentication. A remote unauthenticated attacker may read/write in arbitrary area of the device memory, which may lead to overwriting the firmware, causing a denial-of-service (DoS) condition, and/or arbitrary code execution.
How severe is CVE-2023-22357?
CVE-2023-22357 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.
How is CVE-2023-22357 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2023-22357?
Public advisories list the following as affected: cp1l-el20dr-d, cp1l-el20dr-d firmware. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2023-22357?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
