CVE-2023-38744: Omron CJ1W-EIP21 Firmware

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

Denial-of-service (DoS) vulnerability due to improper validation of specified type of input issue exists in the built-in EtherNet/IP port of the CJ Series CJ2 CPU unit and the communication function of the CS/CJ Series EtherNet/IP unit. If an affected product receives a packet which is specially crafted by a remote unauthenticated attacker, the unit of the affected product may fall into a denial-of-service (DoS) condition. Affected products/versions are as follows: CJ2M CPU Unit CJ2M-CPU3[] Unit version of the built-in EtherNet/IP section Ver. 2.18 and earlier, CJ2H CPU Unit CJ2H-CPU6[]-EIP Unit version of the built-in EtherNet/IP section Ver. 3.04 and earlier, CS/CJ Series EtherNet/IP Unit CS1W-EIP21 V3.04 and earlier, and CS/CJ Series EtherNet/IP Unit CJ1W-EIP21 V3.04 and earlier.

Affected products

  • Omron CJ1W-EIP21 Firmware: up to and including 3.04
  • Omron CJ2H-CPU64-Eip Firmware: up to and including 3.04
  • Omron CJ2H-CPU65-Eip Firmware: up to and including 3.04
  • Omron CJ2H-CPU66-Eip Firmware: up to and including 3.04
  • Omron CJ2H-CPU67-Eip Firmware: up to and including 3.04
  • Omron CJ2H-CPU68-Eip Firmware: up to and including 3.04
  • Omron CJ2M-CPU31 Firmware: up to and including 2.18
  • Omron CJ2M-CPU32 Firmware: up to and including 2.18
  • Omron CJ2M-CPU33 Firmware: up to and including 2.18
  • Omron CJ2M-CPU34 Firmware: up to and including 2.18
  • Omron CJ2M-CPU35 Firmware: up to and including 2.18
  • Omron CS1W-EIP21 Firmware: up to and including 3.04

Published 2023-08-03. Last modified 2026-06-17.