Search

Find a vulnerability

Search criteria

    16 vulnerabilities by yokogawa

    CVE-2024-8110 (GCVE-0-2024-8110)

    Vulnerability from cvelistv5 – Published: 2024-09-17 02:04 – Updated: 2024-09-17 15:04
    VLAI
    Summary
    Denial of Service (DoS) vulnerability has been found in Dual-redundant Platform for Computer. If a computer on which the affected product is installed receives a large number of UDP broadcast packets in a short period, occasionally that computer may restart. If both the active and standby computers are restarted at the same time, the functionality on that computer may be temporarily unavailable.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-17 14:57 UTC
    CWE
    Impacted products
    Vendor Product Version
    Yokogawa Electric Corporation Dual-redundant Platform for Computer (PC2CKM) Affected: R1.01.00 , ≤ R2.03.00 (custom)
    Create a notification for this product.
    yokogawa dual-redundant_platform_for_computer_\(pc2ckm\) Affected: r1.01.00 , ≤ r2.03.00 (custom)
        cpe:2.3:a:yokogawa:dual-redundant_platform_for_computer_\(pc2ckm\):*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-09-17 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:yokogawa:dual-redundant_platform_for_computer_\\(pc2ckm\\):*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dual-redundant_platform_for_computer_\\(pc2ckm\\)",
                "vendor": "yokogawa",
                "versions": [
                  {
                    "lessThanOrEqual": "r2.03.00",
                    "status": "affected",
                    "version": "r1.01.00",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-8110",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-17T14:57:26.649250Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-17T15:04:05.659Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Dual-redundant Platform for Computer (PC2CKM)",
              "vendor": "Yokogawa Electric Corporation",
              "versions": [
                {
                  "lessThanOrEqual": "R2.03.00",
                  "status": "affected",
                  "version": "R1.01.00",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2024-09-17T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Denial of Service (DoS) vulnerability has been found in Dual-redundant Platform for Computer.\u003cbr\u003eIf a computer on which the affected product is installed receives a large number of UDP broadcast packets in a short period, occasionally that computer may restart.\u003cbr\u003eIf both the active and standby computers are restarted at the same time, the functionality on that computer may be temporarily unavailable."
                }
              ],
              "value": "Denial of Service (DoS) vulnerability has been found in Dual-redundant Platform for Computer.\nIf a computer on which the affected product is installed receives a large number of UDP broadcast packets in a short period, occasionally that computer may restart.\nIf both the active and standby computers are restarted at the same time, the functionality on that computer may be temporarily unavailable."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-252",
                  "description": "CWE-252 Unchecked Return Value",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-17T02:04:53.739Z",
            "orgId": "7168b535-132a-4efe-a076-338f829b2eb9",
            "shortName": "YokogawaGroup"
          },
          "references": [
            {
              "url": "https://web-material3.yokogawa.com/1/36276/files/YSAR-24-0003-E.pdf"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7168b535-132a-4efe-a076-338f829b2eb9",
        "assignerShortName": "YokogawaGroup",
        "cveId": "CVE-2024-8110",
        "datePublished": "2024-09-17T02:04:53.739Z",
        "dateReserved": "2024-08-23T01:00:38.184Z",
        "dateUpdated": "2024-09-17T15:04:05.659Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-5650 (GCVE-0-2024-5650)

    Vulnerability from cvelistv5 – Published: 2024-06-17 06:21 – Updated: 2024-08-01 21:18
    VLAI
    Summary
    DLL Hijacking vulnerability has been found in CENTUM CAMS Log server provided by Yokogawa Electric Corporation. If an attacker is somehow able to intrude into a computer that installed affected product or access to a shared folder, by replacing the DLL file with a tampered one, it is possible to execute arbitrary programs with the authority of the SYSTEM account. The affected products and versions are as follows: CENTUM CS 3000 R3.08.10 to R3.09.50 CENTUM VP R4.01.00 to R4.03.00, R5.01.00 to R5.04.20, R6.01.00 to R6.11.10.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-17 13:51 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    Yokogawa Electric Corporation CENTUM CS 3000 Affected: R3.08.10 , ≤ R3.09.50 (custom)
    Create a notification for this product.
    Yokogawa Electric Corporation CENTUM VP Affected: R4.01.00 , ≤ R4.03.00 (custom)
    Affected: R5.01.00 , ≤ R5.04.20 (custom)
    Affected: R6.01.00 , ≤ R6.11.10 (custom)
    Create a notification for this product.
    yokogawa centum_cs_3000 Affected: r3.08.10 , ≤ r3.09.50 (custom)
        cpe:2.3:h:yokogawa:centum_cs_3000:r3.08.10:*:*:*:*:*:*:*
    Create a notification for this product.
    yokogawa centum_vp Affected: r4.01.00 , ≤ f4.03.00 (custom)
        cpe:2.3:a:yokogawa:centum_vp:r4.01.00:*:*:*:-:*:*:*
    Create a notification for this product.
    yokogawa centum_vp Affected: r5.01.00 , ≤ r5.04.20 (custom)
        cpe:2.3:a:yokogawa:centum_vp:r6.01.00:*:*:*:*:*:*:*
    Create a notification for this product.
    yokogawa centum_vp Affected: r6.01.00 , ≤ r6.11.10 (custom)
        cpe:2.3:a:yokogawa:centum_vp:r6.01.00:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-06-17 03:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:yokogawa:centum_cs_3000:r3.08.10:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "centum_cs_3000",
                "vendor": "yokogawa",
                "versions": [
                  {
                    "lessThanOrEqual": "r3.09.50",
                    "status": "affected",
                    "version": "r3.08.10",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:yokogawa:centum_vp:r4.01.00:*:*:*:-:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "centum_vp",
                "vendor": "yokogawa",
                "versions": [
                  {
                    "lessThanOrEqual": "f4.03.00",
                    "status": "affected",
                    "version": "r4.01.00",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:yokogawa:centum_vp:r6.01.00:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "centum_vp",
                "vendor": "yokogawa",
                "versions": [
                  {
                    "lessThanOrEqual": "r5.04.20",
                    "status": "affected",
                    "version": "r5.01.00",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:yokogawa:centum_vp:r6.01.00:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "centum_vp",
                "vendor": "yokogawa",
                "versions": [
                  {
                    "lessThanOrEqual": "r6.11.10",
                    "status": "affected",
                    "version": "r6.01.00",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-5650",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-17T13:51:30.100377Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-17T13:51:32.570Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T21:18:06.883Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://web-material3.yokogawa.com/1/36044/files/YSAR-24-0002-E.pdf"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "CENTUM CS 3000",
              "vendor": "Yokogawa Electric Corporation",
              "versions": [
                {
                  "lessThanOrEqual": "R3.09.50",
                  "status": "affected",
                  "version": "R3.08.10",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "CENTUM VP",
              "vendor": "Yokogawa Electric Corporation",
              "versions": [
                {
                  "lessThanOrEqual": "R4.03.00",
                  "status": "affected",
                  "version": "R4.01.00",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "R5.04.20",
                  "status": "affected",
                  "version": "R5.01.00",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "R6.11.10",
                  "status": "affected",
                  "version": "R6.01.00",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2024-06-17T03:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "DLL Hijacking vulnerability has been found in CENTUM CAMS Log server provided by Yokogawa Electric Corporation. If an attacker is somehow able to intrude into a computer that installed affected product or access to a shared folder, by replacing the DLL file with a tampered one, it is possible to execute arbitrary programs with the authority of the SYSTEM account.\u003cbr\u003e\u003cbr\u003eThe affected products and versions are as follows:\u003cbr\u003eCENTUM CS 3000 R3.08.10 to R3.09.50\u003cbr\u003eCENTUM VP R4.01.00 to R4.03.00, R5.01.00 to R5.04.20, R6.01.00 to R6.11.10."
                }
              ],
              "value": "DLL Hijacking vulnerability has been found in CENTUM CAMS Log server provided by Yokogawa Electric Corporation. If an attacker is somehow able to intrude into a computer that installed affected product or access to a shared folder, by replacing the DLL file with a tampered one, it is possible to execute arbitrary programs with the authority of the SYSTEM account.\n\nThe affected products and versions are as follows:\nCENTUM CS 3000 R3.08.10 to R3.09.50\nCENTUM VP R4.01.00 to R4.03.00, R5.01.00 to R5.04.20, R6.01.00 to R6.11.10."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "CWE-284",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-17T06:21:31.387Z",
            "orgId": "7168b535-132a-4efe-a076-338f829b2eb9",
            "shortName": "YokogawaGroup"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://web-material3.yokogawa.com/1/36044/files/YSAR-24-0002-E.pdf"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7168b535-132a-4efe-a076-338f829b2eb9",
        "assignerShortName": "YokogawaGroup",
        "cveId": "CVE-2024-5650",
        "datePublished": "2024-06-17T06:21:31.387Z",
        "dateReserved": "2024-06-05T05:32:13.103Z",
        "dateUpdated": "2024-08-01T21:18:06.883Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-30997 (GCVE-0-2022-30997)

    Vulnerability from cvelistv5 – Published: 2022-06-28 10:06 – Updated: 2024-08-03 07:03
    VLAI
    Summary
    Use of hard-coded credentials vulnerability exists in STARDOM FCN Controller and FCJ Controller R4.10 to R4.31, which may allow an attacker with an administrative privilege to read/change configuration settings or update the controller with tampered firmware.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-26 19:56 UTC
    CWE
    • Use of Hard-coded Credentials
    • CWE-798 - Use of Hard-coded Credentials
    Impacted products
    Vendor Product Version
    Yokogawa Electric Corporation STARDOM Controller Affected: STARDOM FCN Controller and FCJ Controller R4.10 to R4.31
    Create a notification for this product.
    yokogawa stardom_fcj_firmware Affected: r4.10 , ≤ r4.31 (custom)
        cpe:2.3:o:yokogawa:stardom_fcj_firmware:r4.10:*:*:*:*:*:*:*
    Create a notification for this product.
    yokogawa stardom_fcn_firmware Affected: r4.10 , ≤ r4.31 (custom)
        cpe:2.3:o:yokogawa:stardom_fcn_firmware:r4.10:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:yokogawa:stardom_fcj_firmware:r4.10:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "stardom_fcj_firmware",
                "vendor": "yokogawa",
                "versions": [
                  {
                    "lessThanOrEqual": "r4.31",
                    "status": "affected",
                    "version": "r4.10",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:yokogawa:stardom_fcn_firmware:r4.10:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "stardom_fcn_firmware",
                "vendor": "yokogawa",
                "versions": [
                  {
                    "lessThanOrEqual": "r4.31",
                    "status": "affected",
                    "version": "r4.10",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "HIGH",
                  "attackVector": "ADJACENT_NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 6.3,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "HIGH",
                  "scope": "UNCHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-30997",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-26T19:56:59.327177Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-798",
                    "description": "CWE-798 Use of Hard-coded Credentials",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-26T20:01:46.457Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T07:03:40.234Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://web-material3.yokogawa.com/1/32885/files/YSAR-22-0007-E.pdf"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://web-material3.yokogawa.com/19/32885/files/YSAR-22-0007-J.pdf"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jvn.jp/vu/JVNVU95452299/index.html"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-01"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "STARDOM Controller",
              "vendor": "Yokogawa Electric Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "STARDOM FCN Controller and FCJ Controller R4.10 to R4.31"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Use of hard-coded credentials vulnerability exists in STARDOM FCN Controller and FCJ Controller R4.10 to R4.31, which may allow an attacker with an administrative privilege to read/change configuration settings or update the controller with tampered firmware."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Use of Hard-coded Credentials",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-06-28T10:06:01.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://web-material3.yokogawa.com/1/32885/files/YSAR-22-0007-E.pdf"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://web-material3.yokogawa.com/19/32885/files/YSAR-22-0007-J.pdf"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jvn.jp/vu/JVNVU95452299/index.html"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-01"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vultures@jpcert.or.jp",
              "ID": "CVE-2022-30997",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "STARDOM Controller",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "STARDOM FCN Controller and FCJ Controller R4.10 to R4.31"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Yokogawa Electric Corporation"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Use of hard-coded credentials vulnerability exists in STARDOM FCN Controller and FCJ Controller R4.10 to R4.31, which may allow an attacker with an administrative privilege to read/change configuration settings or update the controller with tampered firmware."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Use of Hard-coded Credentials"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://web-material3.yokogawa.com/1/32885/files/YSAR-22-0007-E.pdf",
                  "refsource": "MISC",
                  "url": "https://web-material3.yokogawa.com/1/32885/files/YSAR-22-0007-E.pdf"
                },
                {
                  "name": "https://web-material3.yokogawa.com/19/32885/files/YSAR-22-0007-J.pdf",
                  "refsource": "MISC",
                  "url": "https://web-material3.yokogawa.com/19/32885/files/YSAR-22-0007-J.pdf"
                },
                {
                  "name": "https://jvn.jp/vu/JVNVU95452299/index.html",
                  "refsource": "MISC",
                  "url": "https://jvn.jp/vu/JVNVU95452299/index.html"
                },
                {
                  "name": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-01",
                  "refsource": "MISC",
                  "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-01"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2022-30997",
        "datePublished": "2022-06-28T10:06:01.000Z",
        "dateReserved": "2022-05-31T00:00:00.000Z",
        "dateUpdated": "2024-08-03T07:03:40.234Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-16232 (GCVE-0-2020-16232)

    Vulnerability from cvelistv5 – Published: 2022-03-18 18:00 – Updated: 2025-04-16 16:41
    VLAI
    Title
    Yokogawa WideField3 Buffer Copy Without Checking Size of Input
    Summary
    In Yokogawa WideField3 R1.01 - R4.03, a buffer overflow could be caused when a user loads a maliciously crafted project file.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-16 15:55 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    Yokogawa WideField3 Affected: R1.01 , ≤ R4.03 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T13:37:54.174Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-20-273-02"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://www.yokogawa.com/library/resources/white-papers/yokogawa-security-advisory-report-list/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2020-16232",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-16T15:55:36.631941Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-16T16:41:56.260Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "WideField3",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "lessThanOrEqual": "R4.03",
                  "status": "affected",
                  "version": "R1.01",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Parity Dynamics reported this vulnerability to CISA."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In Yokogawa WideField3 R1.01 - R4.03, a buffer overflow could be caused when a user loads a maliciously crafted project file."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "LOW",
                "baseScore": 2.8,
                "baseSeverity": "LOW",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-120",
                  "description": "CWE-120 Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-03-18T18:00:29.000Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-20-273-02"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.yokogawa.com/library/resources/white-papers/yokogawa-security-advisory-report-list/"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Yokogawa has prepared revision R4.04 to address this vulnerability and recommends that users switch to this revision.\n\nFor more information about this vulnerability and the associated mitigations, please see Yokogawa\u2019s security advisory report YSAR-20-0002"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Yokogawa WideField3 Buffer Copy Without Checking Size of Input",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "ics-cert@hq.dhs.gov",
              "ID": "CVE-2020-16232",
              "STATE": "PUBLIC",
              "TITLE": "Yokogawa WideField3 Buffer Copy Without Checking Size of Input"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "WideField3",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c=",
                                "version_name": "R1.01",
                                "version_value": "R4.03"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Yokogawa"
                  }
                ]
              }
            },
            "credit": [
              {
                "lang": "eng",
                "value": "Parity Dynamics reported this vulnerability to CISA."
              }
            ],
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "In Yokogawa WideField3 R1.01 - R4.03, a buffer overflow could be caused when a user loads a maliciously crafted project file."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "LOW",
                "baseScore": 2.8,
                "baseSeverity": "LOW",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-120 Buffer Overflow"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://www.cisa.gov/uscert/ics/advisories/icsa-20-273-02",
                  "refsource": "CONFIRM",
                  "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-20-273-02"
                },
                {
                  "name": "https://www.yokogawa.com/library/resources/white-papers/yokogawa-security-advisory-report-list/",
                  "refsource": "CONFIRM",
                  "url": "https://www.yokogawa.com/library/resources/white-papers/yokogawa-security-advisory-report-list/"
                }
              ]
            },
            "solution": [
              {
                "lang": "en",
                "value": "Yokogawa has prepared revision R4.04 to address this vulnerability and recommends that users switch to this revision.\n\nFor more information about this vulnerability and the associated mitigations, please see Yokogawa\u2019s security advisory report YSAR-20-0002"
              }
            ],
            "source": {
              "discovery": "EXTERNAL"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2020-16232",
        "datePublished": "2022-03-18T18:00:29.000Z",
        "dateReserved": "2020-07-31T00:00:00.000Z",
        "dateUpdated": "2025-04-16T16:41:56.260Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2015-5626 (GCVE-0-2015-5626)

    Vulnerability from cvelistv5 – Published: 2020-02-05 18:46 – Updated: 2024-08-06 06:59
    VLAI
    Summary
    Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and earlier, Exaquantum/Batch R2.50.30 and earlier, Exapilot R3.96.10 and earlier, Exaplog R3.40.00 and earlier, Exasmoc R4.03.20 and earlier, Exarqe R4.03.20 and earlier, Field Wireless Device OPC Server R2.01.02 and earlier, PRM R3.12.00 and earlier, STARDOM VDS R7.30.01 and earlier, STARDOM OPC Server for Windows R3.40 and earlier, FAST/TOOLS R10.01 and earlier, B/M9000CS R5.05.01 and earlier, B/M9000 VP R7.03.04 and earlier, and FieldMate R1.01 or R1.02 allows remote attackers to cause a denial of service (network-communications outage) via a crafted packet.
    Severity
    No CVSS data available.
    CWE
    • Buffer Overflow
    References
    Impacted products
    Vendor Product Version
    Yokogawa CENTUM CS 1000 Affected: R3.08.70 and earlier
    Create a notification for this product.
    Yokogawa CENTUM CS 3000 Affected: R3.09.50 and earlier
    Create a notification for this product.
    Yokogawa CENTUM CS 3000 Entry Affected: R3.09.50 and earlier
    Create a notification for this product.
    Yokogawa CENTUM VP Affected: R5.04.20 and earlier
    Create a notification for this product.
    Yokogawa CENTUM VP Entry Affected: R5.04.20 and earlier
    Create a notification for this product.
    Yokogawa ProSafe-RS Affected: R3.02.10 and earlier
    Create a notification for this product.
    Yokogawa Exaopc Affected: R3.72.00 and earlier
    Create a notification for this product.
    Yokogawa Exaquantum Affected: R2.85.00 and earlier
    Create a notification for this product.
    Yokogawa Exaquantum/Batch Affected: R2.50.30 and earlier
    Create a notification for this product.
    Yokogawa Exapilot Affected: R3.96.10 and earlier
    Create a notification for this product.
    Yokogawa Exaplog Affected: R3.40.00 and earlier
    Create a notification for this product.
    Yokogawa Exasmoc Affected: R4.03.20 and earlier
    Create a notification for this product.
    Yokogawa Exarqe Affected: R4.03.20 and earlier
    Create a notification for this product.
    Yokogawa Field Wireless Device OPC Server Affected: R2.01.02 and earlier
    Create a notification for this product.
    Yokogawa PRM Affected: R3.12.00 and earlier
    Create a notification for this product.
    Yokogawa STARDOM VDS Affected: R7.30.01 and earlier
    Create a notification for this product.
    Yokogawa STARDOM OPC Server for Windows Affected: R3.40 and earlier
    Create a notification for this product.
    Yokogawa FAST/TOOLS Affected: R10.01 and earlier
    Create a notification for this product.
    Yokogawa B/M9000CS Affected: R5.05.01 and earlier
    Create a notification for this product.
    Yokogawa B/M9000 VP Affected: R7.03.04 and earlier
    Create a notification for this product.
    Yokogawa FieldMate Affected: R1.01
    Affected: R1.02
    Create a notification for this product.
    Date Public
    2015-09-10 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T06:59:02.787Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://ics-cert.us-cert.gov/advisories/ICSA-15-253-01"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.yokogawa.com/dcs/security/ysar/YSAR-15-0003E.pdf"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CENTUM CS 1000",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.08.70 and earlier"
                }
              ]
            },
            {
              "product": "CENTUM CS 3000",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.09.50 and earlier"
                }
              ]
            },
            {
              "product": "CENTUM CS 3000 Entry",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.09.50 and earlier"
                }
              ]
            },
            {
              "product": "CENTUM VP",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R5.04.20 and earlier"
                }
              ]
            },
            {
              "product": "CENTUM VP Entry",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R5.04.20 and earlier"
                }
              ]
            },
            {
              "product": "ProSafe-RS",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.02.10 and earlier"
                }
              ]
            },
            {
              "product": "Exaopc",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.72.00 and earlier"
                }
              ]
            },
            {
              "product": "Exaquantum",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R2.85.00 and earlier"
                }
              ]
            },
            {
              "product": "Exaquantum/Batch",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R2.50.30 and earlier"
                }
              ]
            },
            {
              "product": "Exapilot",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.96.10 and earlier"
                }
              ]
            },
            {
              "product": "Exaplog",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.40.00 and earlier"
                }
              ]
            },
            {
              "product": "Exasmoc",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R4.03.20 and earlier"
                }
              ]
            },
            {
              "product": "Exarqe",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R4.03.20 and earlier"
                }
              ]
            },
            {
              "product": "Field Wireless Device OPC Server",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R2.01.02 and earlier"
                }
              ]
            },
            {
              "product": "PRM",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.12.00 and earlier"
                }
              ]
            },
            {
              "product": "STARDOM VDS",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R7.30.01 and earlier"
                }
              ]
            },
            {
              "product": "STARDOM OPC Server for Windows",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.40 and earlier"
                }
              ]
            },
            {
              "product": "FAST/TOOLS",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R10.01 and earlier"
                }
              ]
            },
            {
              "product": "B/M9000CS",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R5.05.01 and earlier"
                }
              ]
            },
            {
              "product": "B/M9000 VP",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R7.03.04 and earlier"
                }
              ]
            },
            {
              "product": "FieldMate",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R1.01"
                },
                {
                  "status": "affected",
                  "version": "R1.02"
                }
              ]
            }
          ],
          "datePublic": "2015-09-10T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and earlier, Exaquantum/Batch R2.50.30 and earlier, Exapilot R3.96.10 and earlier, Exaplog R3.40.00 and earlier, Exasmoc R4.03.20 and earlier, Exarqe R4.03.20 and earlier, Field Wireless Device OPC Server R2.01.02 and earlier, PRM R3.12.00 and earlier, STARDOM VDS R7.30.01 and earlier, STARDOM OPC Server for Windows R3.40 and earlier, FAST/TOOLS R10.01 and earlier, B/M9000CS R5.05.01 and earlier, B/M9000 VP R7.03.04 and earlier, and FieldMate R1.01 or R1.02 allows remote attackers to cause a denial of service (network-communications outage) via a crafted packet."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Buffer Overflow",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2020-02-05T18:46:05.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://ics-cert.us-cert.gov/advisories/ICSA-15-253-01"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.yokogawa.com/dcs/security/ysar/YSAR-15-0003E.pdf"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vultures@jpcert.or.jp",
              "ID": "CVE-2015-5626",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CENTUM CS 1000",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.08.70 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CENTUM CS 3000",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.09.50 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CENTUM CS 3000 Entry",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.09.50 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CENTUM VP",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R5.04.20 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CENTUM VP Entry",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R5.04.20 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "ProSafe-RS",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.02.10 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Exaopc",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.72.00 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Exaquantum",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R2.85.00 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Exaquantum/Batch",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R2.50.30 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Exapilot",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.96.10 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Exaplog",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.40.00 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Exasmoc",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R4.03.20 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Exarqe",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R4.03.20 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Field Wireless Device OPC Server",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R2.01.02 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "PRM",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.12.00 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "STARDOM VDS",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R7.30.01 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "STARDOM OPC Server for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.40 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FAST/TOOLS",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R10.01 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "B/M9000CS",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R5.05.01 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "B/M9000 VP",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R7.03.04 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FieldMate",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R1.01"
                              },
                              {
                                "version_value": "R1.02"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Yokogawa"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and earlier, Exaquantum/Batch R2.50.30 and earlier, Exapilot R3.96.10 and earlier, Exaplog R3.40.00 and earlier, Exasmoc R4.03.20 and earlier, Exarqe R4.03.20 and earlier, Field Wireless Device OPC Server R2.01.02 and earlier, PRM R3.12.00 and earlier, STARDOM VDS R7.30.01 and earlier, STARDOM OPC Server for Windows R3.40 and earlier, FAST/TOOLS R10.01 and earlier, B/M9000CS R5.05.01 and earlier, B/M9000 VP R7.03.04 and earlier, and FieldMate R1.01 or R1.02 allows remote attackers to cause a denial of service (network-communications outage) via a crafted packet."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Buffer Overflow"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://ics-cert.us-cert.gov/advisories/ICSA-15-253-01",
                  "refsource": "MISC",
                  "url": "https://ics-cert.us-cert.gov/advisories/ICSA-15-253-01"
                },
                {
                  "name": "http://www.yokogawa.com/dcs/security/ysar/YSAR-15-0003E.pdf",
                  "refsource": "CONFIRM",
                  "url": "http://www.yokogawa.com/dcs/security/ysar/YSAR-15-0003E.pdf"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2015-5626",
        "datePublished": "2020-02-05T18:46:05.000Z",
        "dateReserved": "2015-07-24T00:00:00.000Z",
        "dateUpdated": "2024-08-06T06:59:02.787Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2015-5628 (GCVE-0-2015-5628)

    Vulnerability from cvelistv5 – Published: 2020-02-05 18:46 – Updated: 2024-08-06 06:59
    VLAI
    Summary
    Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and earlier, Exaquantum/Batch R2.50.30 and earlier, Exapilot R3.96.10 and earlier, Exaplog R3.40.00 and earlier, Exasmoc R4.03.20 and earlier, Exarqe R4.03.20 and earlier, Field Wireless Device OPC Server R2.01.02 and earlier, PRM R3.12.00 and earlier, STARDOM VDS R7.30.01 and earlier, STARDOM OPC Server for Windows R3.40 and earlier, FAST/TOOLS R10.01 and earlier, B/M9000CS R5.05.01 and earlier, B/M9000 VP R7.03.04 and earlier, and FieldMate R1.01 or R1.02 allows remote attackers to execute arbitrary code via a crafted packet.
    Severity
    No CVSS data available.
    CWE
    • Buffer Overflow
    References
    Impacted products
    Vendor Product Version
    Yokogawa CENTUM CS 1000 Affected: R3.08.70 and earlier
    Create a notification for this product.
    Yokogawa CENTUM CS 3000 Affected: R3.09.50 and earlier
    Create a notification for this product.
    Yokogawa CENTUM CS 3000 Entry Affected: R3.09.50 and earlier
    Create a notification for this product.
    Yokogawa CENTUM VP Affected: R5.04.20 and earlier
    Create a notification for this product.
    Yokogawa CENTUM VP Entry Affected: R5.04.20 and earlier
    Create a notification for this product.
    Yokogawa ProSafe-RS Affected: R3.02.10 and earlier
    Create a notification for this product.
    Yokogawa Exaopc Affected: R3.72.00 and earlier
    Create a notification for this product.
    Yokogawa Exaquantum Affected: R2.85.00 and earlier
    Create a notification for this product.
    Yokogawa Exaquantum/Batch Affected: R2.50.30 and earlier
    Create a notification for this product.
    Yokogawa Exapilot Affected: R3.96.10 and earlier
    Create a notification for this product.
    Yokogawa Exaplog Affected: R3.40.00 and earlier
    Create a notification for this product.
    Yokogawa Exasmoc Affected: R4.03.20 and earlier
    Create a notification for this product.
    Yokogawa Exarqe Affected: R4.03.20 and earlier
    Create a notification for this product.
    Yokogawa Field Wireless Device OPC Server Affected: R2.01.02 and earlier
    Create a notification for this product.
    Yokogawa PRM Affected: R3.12.00 and earlier
    Create a notification for this product.
    Yokogawa STARDOM VDS Affected: R7.30.01 and earlier
    Create a notification for this product.
    Yokogawa STARDOM OPC Server for Windows Affected: R3.40 and earlier
    Create a notification for this product.
    Yokogawa FAST/TOOLS Affected: R10.01 and earlier
    Create a notification for this product.
    Yokogawa B/M9000CS Affected: R5.05.01 and earlier
    Create a notification for this product.
    Yokogawa B/M9000 VP Affected: R7.03.04 and earlier
    Create a notification for this product.
    Yokogawa FieldMate Affected: R1.01
    Affected: R1.02
    Create a notification for this product.
    Date Public
    2015-09-10 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T06:59:02.677Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://ics-cert.us-cert.gov/advisories/ICSA-15-253-01"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.yokogawa.com/dcs/security/ysar/YSAR-15-0003E.pdf"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CENTUM CS 1000",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.08.70 and earlier"
                }
              ]
            },
            {
              "product": "CENTUM CS 3000",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.09.50 and earlier"
                }
              ]
            },
            {
              "product": "CENTUM CS 3000 Entry",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.09.50 and earlier"
                }
              ]
            },
            {
              "product": "CENTUM VP",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R5.04.20 and earlier"
                }
              ]
            },
            {
              "product": "CENTUM VP Entry",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R5.04.20 and earlier"
                }
              ]
            },
            {
              "product": "ProSafe-RS",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.02.10 and earlier"
                }
              ]
            },
            {
              "product": "Exaopc",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.72.00 and earlier"
                }
              ]
            },
            {
              "product": "Exaquantum",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R2.85.00 and earlier"
                }
              ]
            },
            {
              "product": "Exaquantum/Batch",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R2.50.30 and earlier"
                }
              ]
            },
            {
              "product": "Exapilot",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.96.10 and earlier"
                }
              ]
            },
            {
              "product": "Exaplog",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.40.00 and earlier"
                }
              ]
            },
            {
              "product": "Exasmoc",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R4.03.20 and earlier"
                }
              ]
            },
            {
              "product": "Exarqe",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R4.03.20 and earlier"
                }
              ]
            },
            {
              "product": "Field Wireless Device OPC Server",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R2.01.02 and earlier"
                }
              ]
            },
            {
              "product": "PRM",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.12.00 and earlier"
                }
              ]
            },
            {
              "product": "STARDOM VDS",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R7.30.01 and earlier"
                }
              ]
            },
            {
              "product": "STARDOM OPC Server for Windows",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.40 and earlier"
                }
              ]
            },
            {
              "product": "FAST/TOOLS",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R10.01 and earlier"
                }
              ]
            },
            {
              "product": "B/M9000CS",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R5.05.01 and earlier"
                }
              ]
            },
            {
              "product": "B/M9000 VP",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R7.03.04 and earlier"
                }
              ]
            },
            {
              "product": "FieldMate",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R1.01"
                },
                {
                  "status": "affected",
                  "version": "R1.02"
                }
              ]
            }
          ],
          "datePublic": "2015-09-10T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and earlier, Exaquantum/Batch R2.50.30 and earlier, Exapilot R3.96.10 and earlier, Exaplog R3.40.00 and earlier, Exasmoc R4.03.20 and earlier, Exarqe R4.03.20 and earlier, Field Wireless Device OPC Server R2.01.02 and earlier, PRM R3.12.00 and earlier, STARDOM VDS R7.30.01 and earlier, STARDOM OPC Server for Windows R3.40 and earlier, FAST/TOOLS R10.01 and earlier, B/M9000CS R5.05.01 and earlier, B/M9000 VP R7.03.04 and earlier, and FieldMate R1.01 or R1.02 allows remote attackers to execute arbitrary code via a crafted packet."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Buffer Overflow",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2020-02-05T18:46:01.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://ics-cert.us-cert.gov/advisories/ICSA-15-253-01"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.yokogawa.com/dcs/security/ysar/YSAR-15-0003E.pdf"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vultures@jpcert.or.jp",
              "ID": "CVE-2015-5628",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CENTUM CS 1000",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.08.70 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CENTUM CS 3000",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.09.50 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CENTUM CS 3000 Entry",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.09.50 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CENTUM VP",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R5.04.20 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CENTUM VP Entry",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R5.04.20 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "ProSafe-RS",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.02.10 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Exaopc",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.72.00 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Exaquantum",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R2.85.00 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Exaquantum/Batch",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R2.50.30 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Exapilot",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.96.10 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Exaplog",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.40.00 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Exasmoc",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R4.03.20 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Exarqe",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R4.03.20 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Field Wireless Device OPC Server",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R2.01.02 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "PRM",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.12.00 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "STARDOM VDS",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R7.30.01 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "STARDOM OPC Server for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.40 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FAST/TOOLS",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R10.01 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "B/M9000CS",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R5.05.01 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "B/M9000 VP",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R7.03.04 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FieldMate",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R1.01"
                              },
                              {
                                "version_value": "R1.02"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Yokogawa"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and earlier, Exaquantum/Batch R2.50.30 and earlier, Exapilot R3.96.10 and earlier, Exaplog R3.40.00 and earlier, Exasmoc R4.03.20 and earlier, Exarqe R4.03.20 and earlier, Field Wireless Device OPC Server R2.01.02 and earlier, PRM R3.12.00 and earlier, STARDOM VDS R7.30.01 and earlier, STARDOM OPC Server for Windows R3.40 and earlier, FAST/TOOLS R10.01 and earlier, B/M9000CS R5.05.01 and earlier, B/M9000 VP R7.03.04 and earlier, and FieldMate R1.01 or R1.02 allows remote attackers to execute arbitrary code via a crafted packet."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Buffer Overflow"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://ics-cert.us-cert.gov/advisories/ICSA-15-253-01",
                  "refsource": "MISC",
                  "url": "https://ics-cert.us-cert.gov/advisories/ICSA-15-253-01"
                },
                {
                  "name": "http://www.yokogawa.com/dcs/security/ysar/YSAR-15-0003E.pdf",
                  "refsource": "CONFIRM",
                  "url": "http://www.yokogawa.com/dcs/security/ysar/YSAR-15-0003E.pdf"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2015-5628",
        "datePublished": "2020-02-05T18:46:01.000Z",
        "dateReserved": "2015-07-24T00:00:00.000Z",
        "dateUpdated": "2024-08-06T06:59:02.677Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2015-5627 (GCVE-0-2015-5627)

    Vulnerability from cvelistv5 – Published: 2020-02-05 18:45 – Updated: 2024-08-06 06:59
    VLAI
    Summary
    Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and earlier, Exaquantum/Batch R2.50.30 and earlier, Exapilot R3.96.10 and earlier, Exaplog R3.40.00 and earlier, Exasmoc R4.03.20 and earlier, Exarqe R4.03.20 and earlier, Field Wireless Device OPC Server R2.01.02 and earlier, PRM R3.12.00 and earlier, STARDOM VDS R7.30.01 and earlier, STARDOM OPC Server for Windows R3.40 and earlier, FAST/TOOLS R10.01 and earlier, B/M9000CS R5.05.01 and earlier, B/M9000 VP R7.03.04 and earlier, and FieldMate R1.01 or R1.02 allows remote attackers to cause a denial of service (process outage) via a crafted packet.
    Severity
    No CVSS data available.
    CWE
    • Buffer Overflow
    References
    Impacted products
    Vendor Product Version
    Yokogawa CENTUM CS 1000 Affected: R3.08.70 and earlier
    Create a notification for this product.
    Yokogawa CENTUM CS 3000 Affected: R3.09.50 and earlier
    Create a notification for this product.
    Yokogawa CENTUM CS 3000 Entry Affected: R3.09.50 and earlier
    Create a notification for this product.
    Yokogawa CENTUM VP Affected: R5.04.20 and earlier
    Create a notification for this product.
    Yokogawa CENTUM VP Entry Affected: R5.04.20 and earlier
    Create a notification for this product.
    Yokogawa ProSafe-RS Affected: R3.02.10 and earlier
    Create a notification for this product.
    Yokogawa Exaopc Affected: R3.72.00 and earlier
    Create a notification for this product.
    Yokogawa Exaquantum Affected: R2.85.00 and earlier
    Create a notification for this product.
    Yokogawa Exaquantum/Batch Affected: R2.50.30 and earlier
    Create a notification for this product.
    Yokogawa Exapilot Affected: R3.96.10 and earlier
    Create a notification for this product.
    Yokogawa Exaplog Affected: R3.40.00 and earlier
    Create a notification for this product.
    Yokogawa Exasmoc Affected: R4.03.20 and earlier
    Create a notification for this product.
    Yokogawa Exarqe Affected: R4.03.20 and earlier
    Create a notification for this product.
    Yokogawa Field Wireless Device OPC Server Affected: R2.01.02 and earlier
    Create a notification for this product.
    Yokogawa PRM Affected: R3.12.00 and earlier
    Create a notification for this product.
    Yokogawa STARDOM VDS Affected: R7.30.01 and earlier
    Create a notification for this product.
    Yokogawa STARDOM OPC Server for Windows Affected: R3.40 and earlier
    Create a notification for this product.
    Yokogawa FAST/TOOLS Affected: R10.01 and earlier
    Create a notification for this product.
    Yokogawa B/M9000CS Affected: R5.05.01 and earlier
    Create a notification for this product.
    Yokogawa B/M9000 VP Affected: R7.03.04 and earlier
    Create a notification for this product.
    Yokogawa FieldMate Affected: R1.01
    Affected: R1.02
    Create a notification for this product.
    Date Public
    2015-09-10 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T06:59:02.714Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://ics-cert.us-cert.gov/advisories/ICSA-15-253-01"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.yokogawa.com/dcs/security/ysar/YSAR-15-0003E.pdf"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CENTUM CS 1000",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.08.70 and earlier"
                }
              ]
            },
            {
              "product": "CENTUM CS 3000",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.09.50 and earlier"
                }
              ]
            },
            {
              "product": "CENTUM CS 3000 Entry",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.09.50 and earlier"
                }
              ]
            },
            {
              "product": "CENTUM VP",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R5.04.20 and earlier"
                }
              ]
            },
            {
              "product": "CENTUM VP Entry",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R5.04.20 and earlier"
                }
              ]
            },
            {
              "product": "ProSafe-RS",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.02.10 and earlier"
                }
              ]
            },
            {
              "product": "Exaopc",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.72.00 and earlier"
                }
              ]
            },
            {
              "product": "Exaquantum",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R2.85.00 and earlier"
                }
              ]
            },
            {
              "product": "Exaquantum/Batch",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R2.50.30 and earlier"
                }
              ]
            },
            {
              "product": "Exapilot",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.96.10 and earlier"
                }
              ]
            },
            {
              "product": "Exaplog",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.40.00 and earlier"
                }
              ]
            },
            {
              "product": "Exasmoc",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R4.03.20 and earlier"
                }
              ]
            },
            {
              "product": "Exarqe",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R4.03.20 and earlier"
                }
              ]
            },
            {
              "product": "Field Wireless Device OPC Server",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R2.01.02 and earlier"
                }
              ]
            },
            {
              "product": "PRM",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.12.00 and earlier"
                }
              ]
            },
            {
              "product": "STARDOM VDS",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R7.30.01 and earlier"
                }
              ]
            },
            {
              "product": "STARDOM OPC Server for Windows",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R3.40 and earlier"
                }
              ]
            },
            {
              "product": "FAST/TOOLS",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R10.01 and earlier"
                }
              ]
            },
            {
              "product": "B/M9000CS",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R5.05.01 and earlier"
                }
              ]
            },
            {
              "product": "B/M9000 VP",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R7.03.04 and earlier"
                }
              ]
            },
            {
              "product": "FieldMate",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R1.01"
                },
                {
                  "status": "affected",
                  "version": "R1.02"
                }
              ]
            }
          ],
          "datePublic": "2015-09-10T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and earlier, Exaquantum/Batch R2.50.30 and earlier, Exapilot R3.96.10 and earlier, Exaplog R3.40.00 and earlier, Exasmoc R4.03.20 and earlier, Exarqe R4.03.20 and earlier, Field Wireless Device OPC Server R2.01.02 and earlier, PRM R3.12.00 and earlier, STARDOM VDS R7.30.01 and earlier, STARDOM OPC Server for Windows R3.40 and earlier, FAST/TOOLS R10.01 and earlier, B/M9000CS R5.05.01 and earlier, B/M9000 VP R7.03.04 and earlier, and FieldMate R1.01 or R1.02 allows remote attackers to cause a denial of service (process outage) via a crafted packet."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Buffer Overflow",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2020-02-05T18:45:58.000Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://ics-cert.us-cert.gov/advisories/ICSA-15-253-01"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.yokogawa.com/dcs/security/ysar/YSAR-15-0003E.pdf"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vultures@jpcert.or.jp",
              "ID": "CVE-2015-5627",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "CENTUM CS 1000",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.08.70 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CENTUM CS 3000",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.09.50 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CENTUM CS 3000 Entry",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.09.50 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CENTUM VP",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R5.04.20 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "CENTUM VP Entry",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R5.04.20 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "ProSafe-RS",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.02.10 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Exaopc",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.72.00 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Exaquantum",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R2.85.00 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Exaquantum/Batch",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R2.50.30 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Exapilot",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.96.10 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Exaplog",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.40.00 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Exasmoc",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R4.03.20 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Exarqe",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R4.03.20 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Field Wireless Device OPC Server",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R2.01.02 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "PRM",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.12.00 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "STARDOM VDS",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R7.30.01 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "STARDOM OPC Server for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R3.40 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FAST/TOOLS",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R10.01 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "B/M9000CS",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R5.05.01 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "B/M9000 VP",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R7.03.04 and earlier"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "FieldMate",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R1.01"
                              },
                              {
                                "version_value": "R1.02"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Yokogawa"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and earlier, Exaquantum/Batch R2.50.30 and earlier, Exapilot R3.96.10 and earlier, Exaplog R3.40.00 and earlier, Exasmoc R4.03.20 and earlier, Exarqe R4.03.20 and earlier, Field Wireless Device OPC Server R2.01.02 and earlier, PRM R3.12.00 and earlier, STARDOM VDS R7.30.01 and earlier, STARDOM OPC Server for Windows R3.40 and earlier, FAST/TOOLS R10.01 and earlier, B/M9000CS R5.05.01 and earlier, B/M9000 VP R7.03.04 and earlier, and FieldMate R1.01 or R1.02 allows remote attackers to cause a denial of service (process outage) via a crafted packet."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Buffer Overflow"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://ics-cert.us-cert.gov/advisories/ICSA-15-253-01",
                  "refsource": "MISC",
                  "url": "https://ics-cert.us-cert.gov/advisories/ICSA-15-253-01"
                },
                {
                  "name": "http://www.yokogawa.com/dcs/security/ysar/YSAR-15-0003E.pdf",
                  "refsource": "CONFIRM",
                  "url": "http://www.yokogawa.com/dcs/security/ysar/YSAR-15-0003E.pdf"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2015-5627",
        "datePublished": "2020-02-05T18:45:58.000Z",
        "dateReserved": "2015-07-24T00:00:00.000Z",
        "dateUpdated": "2024-08-06T06:59:02.714Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-17896 (GCVE-0-2018-17896)

    Vulnerability from cvelistv5 – Published: 2018-10-12 14:00 – Updated: 2024-09-17 00:26
    VLAI
    Summary
    Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credentials which may allow an attacker gain unauthorized access to the maintenance functions and obtain or modify information. This attack can be executed only during maintenance work.
    Severity
    No CVSS data available.
    CWE
    • CWE-798 - USE OF HARD-CODED CREDENTIALS CWE-798
    References
    Impacted products
    Vendor Product Version
    Yokogawa STARDOM Controllers FCJ,FCN-100,FCN-RTU, FCN-500 Affected: All versions prior to version X.X
    Create a notification for this product.
    Date Public
    2018-09-28 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T11:01:14.599Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://web-material3.yokogawa.com/YSAR-18-0007-E.pdf"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "STARDOM Controllers FCJ,FCN-100,FCN-RTU, FCN-500",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions prior to version X.X"
                }
              ]
            }
          ],
          "datePublic": "2018-09-28T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credentials which may allow an attacker gain unauthorized access to the maintenance functions and obtain or modify information. This attack can be executed only during maintenance work."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-798",
                  "description": "USE OF HARD-CODED CREDENTIALS CWE-798",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-10-12T13:57:02.000Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://web-material3.yokogawa.com/YSAR-18-0007-E.pdf"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "ics-cert@hq.dhs.gov",
              "DATE_PUBLIC": "2018-09-28T00:00:00",
              "ID": "CVE-2018-17896",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "STARDOM Controllers FCJ,FCN-100,FCN-RTU, FCN-500",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions prior to version X.X"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Yokogawa"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credentials which may allow an attacker gain unauthorized access to the maintenance functions and obtain or modify information. This attack can be executed only during maintenance work."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "USE OF HARD-CODED CREDENTIALS CWE-798"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://web-material3.yokogawa.com/YSAR-18-0007-E.pdf",
                  "refsource": "CONFIRM",
                  "url": "https://web-material3.yokogawa.com/YSAR-18-0007-E.pdf"
                },
                {
                  "name": "https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03",
                  "refsource": "MISC",
                  "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2018-17896",
        "datePublished": "2018-10-12T14:00:00.000Z",
        "dateReserved": "2018-10-02T00:00:00.000Z",
        "dateUpdated": "2024-09-17T00:26:50.260Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-17898 (GCVE-0-2018-17898)

    Vulnerability from cvelistv5 – Published: 2018-10-12 14:00 – Updated: 2024-09-17 01:01
    VLAI
    Summary
    Yokogawa STARDOM Controllers FCJ,FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The controller application fails to prevent memory exhaustion by unauthorized requests. This could allow an attacker to cause the controller to become unstable.
    Severity
    No CVSS data available.
    CWE
    • CWE-400 - UNCONTROLLED RESOURCE CONSUMPTION ('RESOURCE EXHAUSTION') CWE-400
    References
    Impacted products
    Date Public
    2018-09-28 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T11:01:14.517Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://web-material3.yokogawa.com/YSAR-18-0007-E.pdf"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "STARDOM Controllers FCJ,FCN-100,FCN-RTU, FCN-500",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions R4.10 and prior"
                }
              ]
            }
          ],
          "datePublic": "2018-09-28T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Yokogawa STARDOM Controllers FCJ,FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The controller application fails to prevent memory exhaustion by unauthorized requests. This could allow an attacker to cause the controller to become unstable."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": "UNCONTROLLED RESOURCE CONSUMPTION (\u0027RESOURCE EXHAUSTION\u0027) CWE-400",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-10-12T13:57:02.000Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://web-material3.yokogawa.com/YSAR-18-0007-E.pdf"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "ics-cert@hq.dhs.gov",
              "DATE_PUBLIC": "2018-09-28T00:00:00",
              "ID": "CVE-2018-17898",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "STARDOM Controllers FCJ,FCN-100,FCN-RTU, FCN-500",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions R4.10 and prior"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Yokogawa"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Yokogawa STARDOM Controllers FCJ,FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The controller application fails to prevent memory exhaustion by unauthorized requests. This could allow an attacker to cause the controller to become unstable."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "UNCONTROLLED RESOURCE CONSUMPTION (\u0027RESOURCE EXHAUSTION\u0027) CWE-400"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://web-material3.yokogawa.com/YSAR-18-0007-E.pdf",
                  "refsource": "CONFIRM",
                  "url": "https://web-material3.yokogawa.com/YSAR-18-0007-E.pdf"
                },
                {
                  "name": "https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03",
                  "refsource": "MISC",
                  "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2018-17898",
        "datePublished": "2018-10-12T14:00:00.000Z",
        "dateReserved": "2018-10-02T00:00:00.000Z",
        "dateUpdated": "2024-09-17T01:01:51.691Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-17902 (GCVE-0-2018-17902)

    Vulnerability from cvelistv5 – Published: 2018-10-12 14:00 – Updated: 2024-09-16 18:34
    VLAI
    Summary
    Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The application utilizes multiple methods of session management which could result in a denial of service to the remote management functions.
    Severity
    No CVSS data available.
    CWE
    • CWE-384 - SESSION FIXATION CWE-384
    References
    Impacted products
    Date Public
    2018-09-28 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T11:01:14.694Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://web-material3.yokogawa.com/YSAR-18-0007-E.pdf"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "STARDOM Controllers FCJ,FCN-100,FCN-RTU, FCN-500",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions R4.10 and prior"
                }
              ]
            }
          ],
          "datePublic": "2018-09-28T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The application utilizes multiple methods of session management which could result in a denial of service to the remote management functions."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-384",
                  "description": "SESSION FIXATION CWE-384",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-10-12T13:57:02.000Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://web-material3.yokogawa.com/YSAR-18-0007-E.pdf"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "ics-cert@hq.dhs.gov",
              "DATE_PUBLIC": "2018-09-28T00:00:00",
              "ID": "CVE-2018-17902",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "STARDOM Controllers FCJ,FCN-100,FCN-RTU, FCN-500",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions R4.10 and prior"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Yokogawa"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The application utilizes multiple methods of session management which could result in a denial of service to the remote management functions."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "SESSION FIXATION CWE-384"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://web-material3.yokogawa.com/YSAR-18-0007-E.pdf",
                  "refsource": "CONFIRM",
                  "url": "https://web-material3.yokogawa.com/YSAR-18-0007-E.pdf"
                },
                {
                  "name": "https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03",
                  "refsource": "MISC",
                  "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2018-17902",
        "datePublished": "2018-10-12T14:00:00.000Z",
        "dateReserved": "2018-10-02T00:00:00.000Z",
        "dateUpdated": "2024-09-16T18:34:00.672Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-17900 (GCVE-0-2018-17900)

    Vulnerability from cvelistv5 – Published: 2018-10-12 14:00 – Updated: 2024-09-16 19:37
    VLAI
    Summary
    Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which could allow an attacker to obtain credentials for remote access to controllers.
    Severity
    No CVSS data available.
    CWE
    • CWE-522 - INSUFFICIENTLY PROTECTED CREDENTIALS CWE-522
    References
    Impacted products
    Date Public
    2018-09-28 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T11:01:14.563Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://web-material3.yokogawa.com/YSAR-18-0007-E.pdf"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "STARDOM Controllers FCJ,FCN-100,FCN-RTU, FCN-500",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions R4.10 and prior"
                }
              ]
            }
          ],
          "datePublic": "2018-09-28T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which could allow an attacker to obtain credentials for remote access to controllers."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-522",
                  "description": "INSUFFICIENTLY PROTECTED CREDENTIALS CWE-522",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-10-12T13:57:02.000Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://web-material3.yokogawa.com/YSAR-18-0007-E.pdf"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "ics-cert@hq.dhs.gov",
              "DATE_PUBLIC": "2018-09-28T00:00:00",
              "ID": "CVE-2018-17900",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "STARDOM Controllers FCJ,FCN-100,FCN-RTU, FCN-500",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions R4.10 and prior"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Yokogawa"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which could allow an attacker to obtain credentials for remote access to controllers."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "INSUFFICIENTLY PROTECTED CREDENTIALS CWE-522"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://web-material3.yokogawa.com/YSAR-18-0007-E.pdf",
                  "refsource": "CONFIRM",
                  "url": "https://web-material3.yokogawa.com/YSAR-18-0007-E.pdf"
                },
                {
                  "name": "https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03",
                  "refsource": "MISC",
                  "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2018-17900",
        "datePublished": "2018-10-12T14:00:00.000Z",
        "dateReserved": "2018-10-02T00:00:00.000Z",
        "dateUpdated": "2024-09-16T19:37:05.913Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-10592 (GCVE-0-2018-10592)

    Vulnerability from cvelistv5 – Published: 2018-07-31 17:00 – Updated: 2024-09-16 17:38
    VLAI
    Summary
    Yokogawa STARDOM FCJ controllers R4.02 and prior, FCN-100 controllers R4.02 and prior, FCN-RTU controllers R4.02 and prior, and FCN-500 controllers R4.02 and prior utilize hard-coded credentials that could allow an attacker to gain unauthorized administrative access to the device, which could result in remote code execution.
    Severity
    No CVSS data available.
    CWE
    • CWE-798 - USE OF HARD-CODED CREDENTIALS CWE-798
    References
    Date Public
    2018-05-31 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T07:39:08.364Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://web-material3.yokogawa.com/1/6712/details/YSAR-18-0004-E.pdf"
              },
              {
                "name": "104376",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/104376"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "STARDOM FCJ Controllers",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R4.02 and prior"
                }
              ]
            },
            {
              "product": "STARDOM FCN-100 Controllers",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R4.02 and prior"
                }
              ]
            },
            {
              "product": "STARDOM FCN-RTU Controllers",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R4.02 and prior"
                }
              ]
            },
            {
              "product": "STARDOM FCN-500 Controllers",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "status": "affected",
                  "version": "R4.02 and prior"
                }
              ]
            }
          ],
          "datePublic": "2018-05-31T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Yokogawa STARDOM FCJ controllers R4.02 and prior, FCN-100 controllers R4.02 and prior, FCN-RTU controllers R4.02 and prior, and FCN-500 controllers R4.02 and prior utilize hard-coded credentials that could allow an attacker to gain unauthorized administrative access to the device, which could result in remote code execution."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-798",
                  "description": "USE OF HARD-CODED CREDENTIALS CWE-798",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-08-01T09:57:01.000Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://web-material3.yokogawa.com/1/6712/details/YSAR-18-0004-E.pdf"
            },
            {
              "name": "104376",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/104376"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "ics-cert@hq.dhs.gov",
              "DATE_PUBLIC": "2018-05-31T00:00:00",
              "ID": "CVE-2018-10592",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "STARDOM FCJ Controllers",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R4.02 and prior"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "STARDOM FCN-100 Controllers",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R4.02 and prior"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "STARDOM FCN-RTU Controllers",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R4.02 and prior"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "STARDOM FCN-500 Controllers",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "R4.02 and prior"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Yokogawa"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Yokogawa STARDOM FCJ controllers R4.02 and prior, FCN-100 controllers R4.02 and prior, FCN-RTU controllers R4.02 and prior, and FCN-500 controllers R4.02 and prior utilize hard-coded credentials that could allow an attacker to gain unauthorized administrative access to the device, which could result in remote code execution."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "USE OF HARD-CODED CREDENTIALS CWE-798"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://web-material3.yokogawa.com/1/6712/details/YSAR-18-0004-E.pdf",
                  "refsource": "CONFIRM",
                  "url": "https://web-material3.yokogawa.com/1/6712/details/YSAR-18-0004-E.pdf"
                },
                {
                  "name": "104376",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/104376"
                },
                {
                  "name": "https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03",
                  "refsource": "MISC",
                  "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2018-10592",
        "datePublished": "2018-07-31T17:00:00.000Z",
        "dateReserved": "2018-05-01T00:00:00.000Z",
        "dateUpdated": "2024-09-16T17:38:31.810Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2014-0782 (GCVE-0-2014-0782)

    Vulnerability from cvelistv5 – Published: 2014-05-16 10:00 – Updated: 2025-09-25 17:27
    VLAI
    Title
    Yokogawa CENTUM CS 3000 Stack-based Buffer Overflow
    Summary
    Stack-based buffer overflow in BKESimmgr.exe in the Expanded Test Functions package in Yokogawa CENTUM CS 1000, CENTUM CS 3000 Entry Class R3.09.50 and earlier, CENTUM VP R5.03.00 and earlier, CENTUM VP Entry Class R5.03.00 and earlier, Exaopc R3.71.02 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier allows remote attackers to execute arbitrary code via a crafted packet.
    Severity
    No CVSS data available.
    CWE
    Impacted products
    Vendor Product Version
    Yokogawa CENTUM CS 3000 Affected: 0 , < R3.09.50 (custom)
    Create a notification for this product.
    Date Public
    2014-03-11 06:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T09:27:19.445Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.yokogawa.com/dcs/security/ysar/YSAR-14-0001E.pdf"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://ics-cert.us-cert.gov/advisories/ICSA-14-133-01"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CENTUM CS 3000",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "lessThan": "R3.09.50",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Juan Vazquez of Rapid7 Inc."
            }
          ],
          "datePublic": "2014-03-11T06:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\n\n\nStack-based buffer overflow in BKESimmgr.exe in the Expanded Test Functions package in Yokogawa CENTUM CS 1000, CENTUM CS 3000 Entry Class R3.09.50 and earlier, CENTUM VP R5.03.00 and earlier, CENTUM VP Entry Class R5.03.00 and earlier, Exaopc R3.71.02 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier allows remote attackers to execute arbitrary code via a crafted packet.\n\n\u003c/p\u003e"
                }
              ],
              "value": "Stack-based buffer overflow in BKESimmgr.exe in the Expanded Test Functions package in Yokogawa CENTUM CS 1000, CENTUM CS 3000 Entry Class R3.09.50 and earlier, CENTUM VP R5.03.00 and earlier, CENTUM VP Entry Class R5.03.00 and earlier, Exaopc R3.71.02 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier allows remote attackers to execute arbitrary code via a crafted packet."
            }
          ],
          "metrics": [
            {
              "cvssV2_0": {
                "accessComplexity": "MEDIUM",
                "accessVector": "NETWORK",
                "authentication": "NONE",
                "availabilityImpact": "COMPLETE",
                "baseScore": 8.3,
                "confidentialityImpact": "PARTIAL",
                "integrityImpact": "PARTIAL",
                "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:C",
                "version": "2.0"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-09-25T17:27:46.585Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-14-070-01a"
            },
            {
              "name": "66130",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/66130"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://community.rapid7.com/community/metasploit/blog/2014/03/10/yokogawa-centum-cs3000-vulnerabilities"
            },
            {
              "url": "http://www.yokogawa.com/dcs/security/ysar/dcs-ysar-index-en.htm."
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eYokogawa has created a patch (CENTUM CS 3000 R3.09.73 and R3.09.75) to mitigate the reported vulnerabilities. To activate the patch software, the computer needs to be rebooted. Older versions of the CENTUM CS 3000 will need to be updated to the latest version of R3.09.50 before installing the patch software.\u003cbr\u003e\u003c/p\u003e\u003cp\u003eYokogawa also suggests all customers introduce appropriate security measures to the overall system, not just for the vulnerabilities identified.\u003c/p\u003e\u003cp\u003eFor more information, please see the advisory that Yokogawa has published regarding this issue here: \u003ca target=\"_blank\" rel=\"nofollow\" href=\"http://www.yokogawa.com/dcs/security/ysar/dcs-ysar-index-en.htm\"\u003ehttp://www.yokogawa.com/dcs/security/ysar/dcs-ysar-index-en.htm\u003c/a\u003e.\u003c/p\u003e\n\n\u003cbr\u003e"
                }
              ],
              "value": "Yokogawa has created a patch (CENTUM CS 3000 R3.09.73 and R3.09.75) to mitigate the reported vulnerabilities. To activate the patch software, the computer needs to be rebooted. Older versions of the CENTUM CS 3000 will need to be updated to the latest version of R3.09.50 before installing the patch software.\n\n\nYokogawa also suggests all customers introduce appropriate security measures to the overall system, not just for the vulnerabilities identified.\n\nFor more information, please see the advisory that Yokogawa has published regarding this issue here:  http://www.yokogawa.com/dcs/security/ysar/dcs-ysar-index-en.htm ."
            }
          ],
          "source": {
            "advisory": "ICSA-14-070-01",
            "discovery": "EXTERNAL"
          },
          "title": "Yokogawa CENTUM CS 3000 Stack-based Buffer Overflow",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "ics-cert@hq.dhs.gov",
              "ID": "CVE-2014-0781",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Heap-based buffer overflow in BKCLogSvr.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via crafted UDP packets."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "http://ics-cert.us-cert.gov/advisories/ICSA-14-070-01",
                  "refsource": "MISC",
                  "url": "http://ics-cert.us-cert.gov/advisories/ICSA-14-070-01"
                },
                {
                  "name": "66130",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/66130"
                },
                {
                  "name": "https://community.rapid7.com/community/metasploit/blog/2014/03/10/yokogawa-centum-cs3000-vulnerabilities",
                  "refsource": "MISC",
                  "url": "https://community.rapid7.com/community/metasploit/blog/2014/03/10/yokogawa-centum-cs3000-vulnerabilities"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2014-0782",
        "datePublished": "2014-05-16T10:00:00.000Z",
        "dateReserved": "2014-01-02T00:00:00.000Z",
        "dateUpdated": "2025-09-25T17:27:46.585Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2014-0784 (GCVE-0-2014-0784)

    Vulnerability from cvelistv5 – Published: 2014-03-14 10:00 – Updated: 2025-09-25 17:25
    VLAI
    Title
    Yokogawa CENTUM CS 3000 Stack-based Buffer Overflow
    Summary
    Stack-based buffer overflow in BKBCopyD.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.
    Severity
    No CVSS data available.
    CWE
    Impacted products
    Vendor Product Version
    Yokogawa CENTUM CS 3000 Affected: 0 , < R3.09.50 (custom)
    Create a notification for this product.
    Date Public
    2014-03-11 06:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T09:27:19.533Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://ics-cert.us-cert.gov/advisories/ICSA-14-070-01"
              },
              {
                "name": "66114",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/66114"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://community.rapid7.com/community/metasploit/blog/2014/03/10/yokogawa-centum-cs3000-vulnerabilities"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CENTUM CS 3000",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "lessThan": "R3.09.50",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Juan Vazquez of Rapid7 Inc."
            }
          ],
          "datePublic": "2014-03-11T06:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\n\nStack-based buffer overflow in BKBCopyD.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.\n\n\u003c/p\u003e"
                }
              ],
              "value": "Stack-based buffer overflow in BKBCopyD.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet."
            }
          ],
          "metrics": [
            {
              "cvssV2_0": {
                "accessComplexity": "MEDIUM",
                "accessVector": "NETWORK",
                "authentication": "NONE",
                "availabilityImpact": "COMPLETE",
                "baseScore": 8.3,
                "confidentialityImpact": "PARTIAL",
                "integrityImpact": "PARTIAL",
                "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:C",
                "version": "2.0"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-09-25T17:25:47.981Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-14-070-01a"
            },
            {
              "name": "66130",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/66130"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://community.rapid7.com/community/metasploit/blog/2014/03/10/yokogawa-centum-cs3000-vulnerabilities"
            },
            {
              "url": "http://www.yokogawa.com/dcs/security/ysar/dcs-ysar-index-en.htm."
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eYokogawa has created a patch (CENTUM CS 3000 R3.09.73 and R3.09.75) to mitigate the reported vulnerabilities. To activate the patch software, the computer needs to be rebooted. Older versions of the CENTUM CS 3000 will need to be updated to the latest version of R3.09.50 before installing the patch software.\u003cbr\u003e\u003c/p\u003e\u003cp\u003eYokogawa also suggests all customers introduce appropriate security measures to the overall system, not just for the vulnerabilities identified.\u003c/p\u003e\u003cp\u003eFor more information, please see the advisory that Yokogawa has published regarding this issue here: \u003ca target=\"_blank\" rel=\"nofollow\" href=\"http://www.yokogawa.com/dcs/security/ysar/dcs-ysar-index-en.htm\"\u003ehttp://www.yokogawa.com/dcs/security/ysar/dcs-ysar-index-en.htm\u003c/a\u003e.\u003c/p\u003e\n\n\u003cbr\u003e"
                }
              ],
              "value": "Yokogawa has created a patch (CENTUM CS 3000 R3.09.73 and R3.09.75) to mitigate the reported vulnerabilities. To activate the patch software, the computer needs to be rebooted. Older versions of the CENTUM CS 3000 will need to be updated to the latest version of R3.09.50 before installing the patch software.\n\n\nYokogawa also suggests all customers introduce appropriate security measures to the overall system, not just for the vulnerabilities identified.\n\nFor more information, please see the advisory that Yokogawa has published regarding this issue here:  http://www.yokogawa.com/dcs/security/ysar/dcs-ysar-index-en.htm ."
            }
          ],
          "source": {
            "advisory": "ICSA-14-070-01",
            "discovery": "EXTERNAL"
          },
          "title": "Yokogawa CENTUM CS 3000 Stack-based Buffer Overflow",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "ics-cert@hq.dhs.gov",
              "ID": "CVE-2014-0781",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Heap-based buffer overflow in BKCLogSvr.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via crafted UDP packets."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "http://ics-cert.us-cert.gov/advisories/ICSA-14-070-01",
                  "refsource": "MISC",
                  "url": "http://ics-cert.us-cert.gov/advisories/ICSA-14-070-01"
                },
                {
                  "name": "66130",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/66130"
                },
                {
                  "name": "https://community.rapid7.com/community/metasploit/blog/2014/03/10/yokogawa-centum-cs3000-vulnerabilities",
                  "refsource": "MISC",
                  "url": "https://community.rapid7.com/community/metasploit/blog/2014/03/10/yokogawa-centum-cs3000-vulnerabilities"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2014-0784",
        "datePublished": "2014-03-14T10:00:00.000Z",
        "dateReserved": "2014-01-02T00:00:00.000Z",
        "dateUpdated": "2025-09-25T17:25:47.981Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2014-0781 (GCVE-0-2014-0781)

    Vulnerability from cvelistv5 – Published: 2014-03-14 10:00 – Updated: 2025-09-25 17:22
    VLAI
    Title
    Yokogawa CENTUM CS 3000 Heap-based Buffer Overflow
    Summary
    Heap-based buffer overflow in BKCLogSvr.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via crafted UDP packets.
    Severity
    No CVSS data available.
    CWE
    Impacted products
    Vendor Product Version
    Yokogawa CENTUM CS 3000 Affected: 0 , < R3.09.50 (custom)
    Create a notification for this product.
    Date Public
    2014-03-11 06:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T09:27:19.535Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://ics-cert.us-cert.gov/advisories/ICSA-14-070-01"
              },
              {
                "name": "66130",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/66130"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://community.rapid7.com/community/metasploit/blog/2014/03/10/yokogawa-centum-cs3000-vulnerabilities"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CENTUM CS 3000",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "lessThan": "R3.09.50",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Juan Vazquez of Rapid7 Inc."
            }
          ],
          "datePublic": "2014-03-11T06:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eHeap-based buffer overflow in BKCLogSvr.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via crafted UDP packets.\u003c/p\u003e"
                }
              ],
              "value": "Heap-based buffer overflow in BKCLogSvr.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via crafted UDP packets."
            }
          ],
          "metrics": [
            {
              "cvssV2_0": {
                "accessComplexity": "MEDIUM",
                "accessVector": "NETWORK",
                "authentication": "NONE",
                "availabilityImpact": "COMPLETE",
                "baseScore": 9.3,
                "confidentialityImpact": "COMPLETE",
                "integrityImpact": "COMPLETE",
                "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
                "version": "2.0"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-122",
                  "description": "CWE-122",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-09-25T17:22:27.951Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-14-070-01a"
            },
            {
              "name": "66130",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/66130"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://community.rapid7.com/community/metasploit/blog/2014/03/10/yokogawa-centum-cs3000-vulnerabilities"
            },
            {
              "url": "http://www.yokogawa.com/dcs/security/ysar/dcs-ysar-index-en.htm."
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eYokogawa has created a patch (CENTUM CS 3000 R3.09.73 and R3.09.75) to mitigate the reported vulnerabilities. To activate the patch software, the computer needs to be rebooted. Older versions of the CENTUM CS 3000 will need to be updated to the latest version of R3.09.50 before installing the patch software.\u003cbr\u003e\u003c/p\u003e\u003cp\u003eYokogawa also suggests all customers introduce appropriate security measures to the overall system, not just for the vulnerabilities identified.\u003c/p\u003e\u003cp\u003eFor more information, please see the advisory that Yokogawa has published regarding this issue here: \u003ca target=\"_blank\" rel=\"nofollow\" href=\"http://www.yokogawa.com/dcs/security/ysar/dcs-ysar-index-en.htm\"\u003ehttp://www.yokogawa.com/dcs/security/ysar/dcs-ysar-index-en.htm\u003c/a\u003e.\u003c/p\u003e\n\n\u003cbr\u003e"
                }
              ],
              "value": "Yokogawa has created a patch (CENTUM CS 3000 R3.09.73 and R3.09.75) to mitigate the reported vulnerabilities. To activate the patch software, the computer needs to be rebooted. Older versions of the CENTUM CS 3000 will need to be updated to the latest version of R3.09.50 before installing the patch software.\n\n\nYokogawa also suggests all customers introduce appropriate security measures to the overall system, not just for the vulnerabilities identified.\n\nFor more information, please see the advisory that Yokogawa has published regarding this issue here:  http://www.yokogawa.com/dcs/security/ysar/dcs-ysar-index-en.htm ."
            }
          ],
          "source": {
            "advisory": "ICSA-14-070-01",
            "discovery": "EXTERNAL"
          },
          "title": "Yokogawa CENTUM CS 3000 Heap-based Buffer Overflow",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "ics-cert@hq.dhs.gov",
              "ID": "CVE-2014-0781",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Heap-based buffer overflow in BKCLogSvr.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via crafted UDP packets."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "http://ics-cert.us-cert.gov/advisories/ICSA-14-070-01",
                  "refsource": "MISC",
                  "url": "http://ics-cert.us-cert.gov/advisories/ICSA-14-070-01"
                },
                {
                  "name": "66130",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/66130"
                },
                {
                  "name": "https://community.rapid7.com/community/metasploit/blog/2014/03/10/yokogawa-centum-cs3000-vulnerabilities",
                  "refsource": "MISC",
                  "url": "https://community.rapid7.com/community/metasploit/blog/2014/03/10/yokogawa-centum-cs3000-vulnerabilities"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2014-0781",
        "datePublished": "2014-03-14T10:00:00.000Z",
        "dateReserved": "2014-01-02T00:00:00.000Z",
        "dateUpdated": "2025-09-25T17:22:27.951Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2014-0783 (GCVE-0-2014-0783)

    Vulnerability from cvelistv5 – Published: 2014-03-14 10:00 – Updated: 2025-09-25 17:24
    VLAI
    Title
    Yokogawa CENTUM CS 3000 Stack-based Buffer Overflow
    Summary
    Stack-based buffer overflow in BKHOdeq.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.
    Severity
    No CVSS data available.
    CWE
    Impacted products
    Vendor Product Version
    Yokogawa CENTUM CS 3000 Affected: 0 , < R3.09.50 (custom)
    Create a notification for this product.
    Date Public
    2014-03-11 06:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T09:27:19.511Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://ics-cert.us-cert.gov/advisories/ICSA-14-070-01"
              },
              {
                "name": "66111",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/66111"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://community.rapid7.com/community/metasploit/blog/2014/03/10/yokogawa-centum-cs3000-vulnerabilities"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CENTUM CS 3000",
              "vendor": "Yokogawa",
              "versions": [
                {
                  "lessThan": "R3.09.50",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Juan Vazquez of Rapid7 Inc."
            }
          ],
          "datePublic": "2014-03-11T06:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\nStack-based buffer overflow in BKHOdeq.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.\n\n\u003c/p\u003e"
                }
              ],
              "value": "Stack-based buffer overflow in BKHOdeq.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet."
            }
          ],
          "metrics": [
            {
              "cvssV2_0": {
                "accessComplexity": "LOW",
                "accessVector": "NETWORK",
                "authentication": "NONE",
                "availabilityImpact": "COMPLETE",
                "baseScore": 9,
                "confidentialityImpact": "PARTIAL",
                "integrityImpact": "PARTIAL",
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:C",
                "version": "2.0"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-09-25T17:24:25.563Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-14-070-01a"
            },
            {
              "name": "66130",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/66130"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://community.rapid7.com/community/metasploit/blog/2014/03/10/yokogawa-centum-cs3000-vulnerabilities"
            },
            {
              "url": "http://www.yokogawa.com/dcs/security/ysar/dcs-ysar-index-en.htm."
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eYokogawa has created a patch (CENTUM CS 3000 R3.09.73 and R3.09.75) to mitigate the reported vulnerabilities. To activate the patch software, the computer needs to be rebooted. Older versions of the CENTUM CS 3000 will need to be updated to the latest version of R3.09.50 before installing the patch software.\u003cbr\u003e\u003c/p\u003e\u003cp\u003eYokogawa also suggests all customers introduce appropriate security measures to the overall system, not just for the vulnerabilities identified.\u003c/p\u003e\u003cp\u003eFor more information, please see the advisory that Yokogawa has published regarding this issue here: \u003ca target=\"_blank\" rel=\"nofollow\" href=\"http://www.yokogawa.com/dcs/security/ysar/dcs-ysar-index-en.htm\"\u003ehttp://www.yokogawa.com/dcs/security/ysar/dcs-ysar-index-en.htm\u003c/a\u003e.\u003c/p\u003e\n\n\u003cbr\u003e"
                }
              ],
              "value": "Yokogawa has created a patch (CENTUM CS 3000 R3.09.73 and R3.09.75) to mitigate the reported vulnerabilities. To activate the patch software, the computer needs to be rebooted. Older versions of the CENTUM CS 3000 will need to be updated to the latest version of R3.09.50 before installing the patch software.\n\n\nYokogawa also suggests all customers introduce appropriate security measures to the overall system, not just for the vulnerabilities identified.\n\nFor more information, please see the advisory that Yokogawa has published regarding this issue here:  http://www.yokogawa.com/dcs/security/ysar/dcs-ysar-index-en.htm ."
            }
          ],
          "source": {
            "advisory": "ICSA-14-070-01",
            "discovery": "EXTERNAL"
          },
          "title": "Yokogawa CENTUM CS 3000 Stack-based Buffer Overflow",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "ics-cert@hq.dhs.gov",
              "ID": "CVE-2014-0781",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Heap-based buffer overflow in BKCLogSvr.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via crafted UDP packets."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "http://ics-cert.us-cert.gov/advisories/ICSA-14-070-01",
                  "refsource": "MISC",
                  "url": "http://ics-cert.us-cert.gov/advisories/ICSA-14-070-01"
                },
                {
                  "name": "66130",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/66130"
                },
                {
                  "name": "https://community.rapid7.com/community/metasploit/blog/2014/03/10/yokogawa-centum-cs3000-vulnerabilities",
                  "refsource": "MISC",
                  "url": "https://community.rapid7.com/community/metasploit/blog/2014/03/10/yokogawa-centum-cs3000-vulnerabilities"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2014-0783",
        "datePublished": "2014-03-14T10:00:00.000Z",
        "dateReserved": "2014-01-02T00:00:00.000Z",
        "dateUpdated": "2025-09-25T17:24:25.563Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }