Heap-based buffer overflow in BKCLogSvr.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via crafted UDP packets.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-122,CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| yokogawa | centum_cs_3000 | r3.05 |
| yokogawa | centum_cs_3000 | r3.03 |
| yokogawa | centum_cs_3000 | r3.09 |
| yokogawa | centum_cs_3000 | r3.08 |
| yokogawa | centum_cs_3000 | r3.02 |
| yokogawa | centum_cs_3000 | r3.08.50 |
| yokogawa | centum_cs_3000 | r3.04 |
| yokogawa | centum_cs_3000 | r3.08.70 |
| yokogawa | centum_cs_3000 | r3.06 |
| yokogawa | centum_cs_3000 | r3.07 |
| yokogawa | centum_cs_3000 | * |
| yokogawa | centum_cs_3000 | r3.01 |
Stack-based buffer overflow in BKESimmgr.exe in the Expanded Test Functions package in Yokogawa CENTUM CS 1000, CENTUM CS 3000 Entry Class R3.09.50 and earlier, CENTUM VP R5.03.00 and earlier, CENTUM VP Entry Class R5.03.00 and earlier, Exaopc R3.71.02 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier allows remote attackers to execute arbitrary code via a crafted packet.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-121,CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| yokogawa | b/m9000_vp_software | * |
| yokogawa | centum_vp | - |
| yokogawa | b/m9000cs | - |
| yokogawa | centum_vp_entry_class | - |
| yokogawa | centum_cs_3000_entry_class_software | * |
| yokogawa | centum_cs_3000 | - |
| yokogawa | centum_vp_entry_class_software | * |
| yokogawa | exaopc | * |
| yokogawa | centum_cs_1000 | - |
| yokogawa | b/m9000_vp | - |
| yokogawa | b/m9000cs_software | * |
| yokogawa | centum_cs_3000_entry_class | - |
| yokogawa | centum_vp_software | * |
| yokogawa | centum_cs_1000_software | - |
| yokogawa | centum_cs_3000_software | * |
Stack-based buffer overflow in BKHOdeq.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-121,CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| yokogawa | centum_cs_3000 | r3.05 |
| yokogawa | centum_cs_3000 | r3.03 |
| yokogawa | centum_cs_3000 | r3.09 |
| yokogawa | centum_cs_3000 | r3.08 |
| yokogawa | centum_cs_3000 | r3.02 |
| yokogawa | centum_cs_3000 | r3.08.50 |
| yokogawa | centum_cs_3000 | r3.04 |
| yokogawa | centum_cs_3000 | r3.08.70 |
| yokogawa | centum_cs_3000 | r3.06 |
| yokogawa | centum_cs_3000 | r3.07 |
| yokogawa | centum_cs_3000 | * |
| yokogawa | centum_cs_3000 | r3.01 |
Stack-based buffer overflow in BKBCopyD.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-121,CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| yokogawa | centum_cs_3000 | r3.05 |
| yokogawa | centum_cs_3000 | r3.03 |
| yokogawa | centum_cs_3000 | r3.09 |
| yokogawa | centum_cs_3000 | r3.08 |
| yokogawa | centum_cs_3000 | r3.02 |
| yokogawa | centum_cs_3000 | r3.08.50 |
| yokogawa | centum_cs_3000 | r3.04 |
| yokogawa | centum_cs_3000 | r3.08.70 |
| yokogawa | centum_cs_3000 | r3.06 |
| yokogawa | centum_cs_3000 | r3.07 |
| yokogawa | centum_cs_3000 | * |
| yokogawa | centum_cs_3000 | r3.01 |
Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM VP R5.03.20 and earlier, Exaopc R3.72.00 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier, when FCS/Test Function is enabled, allows remote attackers to execute arbitrary code via a crafted packet.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| yokogawa | b/m9000_vp_software | * |
| yokogawa | centum_vp | - |
| yokogawa | exaopc | 3.71.02 |
| yokogawa | b/m9000cs | - |
| yokogawa | centum_vp_entry_class | - |
| yokogawa | centum_cs_3000_entry_class_software | * |
| yokogawa | centum_cs_3000 | - |
| yokogawa | centum_vp_entry_class_software | * |
| yokogawa | exaopc | * |
| yokogawa | centum_cs_1000 | - |
| yokogawa | b/m9000_vp | - |
| yokogawa | b/m9000cs_software | * |
| yokogawa | centum_cs_3000_entry_class | - |
| yokogawa | centum_vp_software | 4.03.00 |
| yokogawa | centum_vp_software | * |
| yokogawa | centum_cs_1000_software | - |
| yokogawa | centum_cs_3000_software | * |
BKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM VP through R4.03.00 and R5.x through R5.04.00, and Exaopc through R3.72.10, does not require authentication, which allows remote attackers to read arbitrary files via a RETR operation, write to arbitrary files via a STOR operation, or obtain sensitive database-location information via a PMODE operation, a different vulnerability than CVE-2014-0784.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| yokogawa | centum_cs_3000 | r3.05 |
| yokogawa | centum_cs_3000 | r3.09.50 |
| yokogawa | centum_cs_3000 | r3.03 |
| yokogawa | centum_cs_3000 | r3.09 |
| yokogawa | centum_vp | r5.01.00 |
| yokogawa | centum_vp | r5.03.00 |
| yokogawa | centum_cs_3000 | r3.08 |
| yokogawa | centum_cs_3000 | r3.02 |
| yokogawa | centum_cs_3000 | r3.08.50 |
| yokogawa | centum_cs_3000 | r3.04 |
| yokogawa | centum_cs_3000 | r3.08.70 |
| yokogawa | exaopc | * |
| yokogawa | centum_cs_3000 | r3.06 |
| yokogawa | centum_cs_3000 | r3.07 |
| yokogawa | centum_cs_3000 | r3.01 |
| yokogawa | centum_vp | r5.01.20 |
| yokogawa | centum_vp | * |
| yokogawa | centum_vp | r5.02.00 |
XML external entity (XXE) vulnerability in the WebHMI server in Yokogawa Electric Corporation FAST/TOOLS before R9.05-SP2 allows local users to cause a denial of service (CPU or network traffic consumption) or read arbitrary files via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| yokogawa | fast/tools | r9.01 |
| yokogawa | fast/tools | r9.04 |
| yokogawa | fast/tools | r9.02 |
| yokogawa | fast/tools | r9.05 |
| yokogawa | fast/tools | r9.03 |
Yokogawa STARDOM FCN/FCJ controller R1.01 through R4.01 does not require authentication for Logic Designer connections, which allows remote attackers to reconfigure the device or cause a denial of service via a (1) stop application program, (2) change value, or (3) modify application command.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| yokogawa | stardom_fcn/fcj | r1.01 |
| yokogawa | stardom_fcn/fcj | r3.01 |
| yokogawa | stardom_fcn/fcj | r2.01 |
| yokogawa | stardom_fcn/fcj | r4.01 |
Buffer overflow in the license management function of YOKOGAWA products (iDefine for ProSafe-RS R1.16.3 and earlier, STARDOM VDS R7.50 and earlier, STARDOM FCN/FCJ Simulator R4.20 and earlier, ASTPLANNER R15.01 and earlier, TriFellows V5.04 and earlier) allows remote attackers to stop the license management function or execute an arbitrary program via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| yokogawa | astplanner | * |
| yokogawa | stardom_versatile_data_server_firmware | * |
| yokogawa | trifellows | * |
| yokogawa | idefine_for_prosafe-rs_firmware | * |
| yokogawa | stardom_fcn/fcj_simulator_firmware | * |
Yokogawa STARDOM FCJ controllers R4.02 and prior, FCN-100 controllers R4.02 and prior, FCN-RTU controllers R4.02 and prior, and FCN-500 controllers R4.02 and prior utilize hard-coded credentials that could allow an attacker to gain unauthorized administrative access to the device, which could result in remote code execution.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-798,CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| yokogawa | fcn-100_firmware | * |
| yokogawa | fcn-500_firmware | * |
| yokogawa | fcj_firmware | * |
| yokogawa | fcn-rtu_firmware | * |
Multiple Yokogawa products that contain Vnet/IP Open Communication Driver (CENTUM CS 3000(R3.05.00 - R3.09.50), CENTUM CS 3000 Entry Class(R3.05.00 - R3.09.50), CENTUM VP(R4.01.00 - R6.03.10), CENTUM VP Entry Class(R4.01.00 - R6.03.10), Exaopc(R3.10.00 - R3.75.00), PRM(R2.06.00 - R3.31.00), ProSafe-RS(R1.02.00 - R4.02.00), FAST/TOOLS(R9.02.00 - R10.02.00), B/M9000 VP(R6.03.01 - R8.01.90)) allows remote attackers to cause a denial of service attack that may result in stopping Vnet/IP Open Communication Driver's communication via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| yokogawa | centum_vp_firmware | * |
| yokogawa | centum_vp_entry_class | * |
| yokogawa | exaopc | * |
| yokogawa | centum_cs_3000_firmware | * |
| yokogawa | fast/tools | * |
| yokogawa | plant_resource_manager | * |
| yokogawa | prosafe-rs | * |
| yokogawa | b/m9000_vp | * |
| yokogawa | centum_cs_3000_entry_class | * |
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credentials which may allow an attacker gain unauthorized access to the maintenance functions and obtain or modify information. This attack can be executed only during maintenance work.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-798,CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| yokogawa | fcn-100_firmware | * |
| yokogawa | fcn-500_firmware | * |
| yokogawa | fcj_firmware | * |
| yokogawa | fcn-rtu_firmware | * |
Yokogawa STARDOM Controllers FCJ,FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The controller application fails to prevent memory exhaustion by unauthorized requests. This could allow an attacker to cause the controller to become unstable.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-400,CWE-400,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| yokogawa | fcn-100_firmware | * |
| yokogawa | fcn-500_firmware | * |
| yokogawa | fcj_firmware | * |
| yokogawa | fcn-rtu_firmware | * |
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which could allow an attacker to obtain credentials for remote access to controllers.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-522,CWE-522,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| yokogawa | fcn-100_firmware | * |
| yokogawa | fcn-500_firmware | * |
| yokogawa | fcj_firmware | * |
| yokogawa | fcn-rtu_firmware | * |
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The application utilizes multiple methods of session management which could result in a denial of service to the remote management functions.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-384,CWE-384,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| yokogawa | fcn-100_firmware | * |
| yokogawa | fcn-500_firmware | * |
| yokogawa | fcj_firmware | * |
| yokogawa | fcn-rtu_firmware | * |
A weakness in access controls in CENTUM CS 1000 all versions, CENTUM CS 3000 versions R3.09.50 and earlier, CENTUM CS 3000 Small versions R3.09.50 and earlier, CENTUM VP versions R6.03.10 and earlier, CENTUM VP Small versions R6.03.10 and earlier, CENTUM VP Basic versions R6.03.10 and earlier, Exaopc versions R3.75.00 and earlier, B/M9000 CS all versions, and B/M9000 VP versions R8.01.01 and earlier may allow a local attacker to exploit the message management function of the system. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H).
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| yokogawa | exaopc | * |
| yokogawa | b/m9000_cs | - |
| yokogawa | centum_cs_3000 | * |
| yokogawa | b/m9000_vp | * |
| yokogawa | centum_vp | * |
License Manager Service of YOKOGAWA products (CENTUM VP (R5.01.00 - R6.06.00), CENTUM VP Entry Class (R5.01.00 - R6.06.00), ProSafe-RS (R3.01.00 - R4.04.00), PRM (R4.01.00 - R4.02.00), B/M9000 VP(R7.01.01 - R8.02.03)) allows remote attackers to bypass access restriction to send malicious files to the PC where License Manager Service runs via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| yokogawa | b/m_9000_vp | * |
| yokogawa | prosafe-rs | * |
| yokogawa | prm | * |
| yokogawa | centum_vp | * |