cbcvebase.

Yokogawa Centum Vp vulnerabilities

9 known vulnerabilities affecting yokogawa/centum_vp.

Total CVEs
9
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH3MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2014-5208P2HIGHCVSS 7.5PoC≤ r4.03.00vr5.01.00+3 more2014-12-22
CVE-2014-5208 [HIGH] CVE-2014-5208: BKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM BKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM VP through R4.03.00 and R5.x through R5.04.00, and Exaopc through R3.72.10, does not require authentication, which allows remote attackers to read arbitrary files via a RETR operation, write to arbitrary files via a STOR operation, or obtain sensitive database-l
nvd
CVE-2015-5628P2CRITICALCVSS 9.8vR5.04.20 and earlier2020-02-05
CVE-2015-5628 [CRITICAL] CWE-787 CVE-2015-5628: Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and earlier, Exaquantum/Batch R2.50.30 and
nvd
CVE-2019-5909P2CRITICALCVSS 9.8≥ r5.01.00, ≤ r6.06.002019-02-13
CVE-2019-5909 [CRITICAL] CWE-287 CVE-2019-5909: License Manager Service of YOKOGAWA products (CENTUM VP (R5.01.00 - R6.06.00), CENTUM VP Entry Class License Manager Service of YOKOGAWA products (CENTUM VP (R5.01.00 - R6.06.00), CENTUM VP Entry Class (R5.01.00 - R6.06.00), ProSafe-RS (R3.01.00 - R4.04.00), PRM (R4.01.00 - R4.02.00), B/M9000 VP(R7.01.01 - R8.02.03)) allows remote attackers to bypass access restriction to send malicious files to the PC where License Manager Service runs via unspeci
nvd
CVE-2015-5627P3CRITICALCVSS 9.8vR5.04.20 and earlier2020-02-05
CVE-2015-5627 [CRITICAL] CWE-787 CVE-2015-5627: Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and earlier, Exaquantum/Batch R2.50.30 and
nvd
CVE-2015-5626P3CRITICALCVSS 9.8vR5.04.20 and earlier2020-02-05
CVE-2015-5626 [CRITICAL] CWE-787 CVE-2015-5626: Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and earlier, Exaquantum/Batch R2.50.30 and
nvd
CVE-2022-26034P3CRITICALCVSS 9.1≥ r6.01.10, ≤ r6.09.00≥ r6.01.10, ≤ r06.09.002022-04-15
CVE-2022-26034 [CRITICAL] CWE-287 CVE-2022-26034: Improper authentication vulnerability in the communication protocol provided by AD (Automation Desig Improper authentication vulnerability in the communication protocol provided by AD (Automation Design) server of CENTUM VP R6.01.10 to R6.09.00, CENTUM VP Small R6.01.10 to R6.09.00, CENTUM VP Basic R6.01.10 to R6.09.00, and B/M9000 VP R8.01.01 to R8.03.01 allows an attacker to use the functions provided by AD server. This may lead to leakage or t
nvd
CVE-2022-27188P3HIGHCVSS 7.8≥ r4.01.00, ≤ r4.03.002022-04-15
CVE-2022-27188 [HIGH] CWE-78 CVE-2022-27188: OS command injection vulnerability exists in CENTUM VP R4.01.00 to R4.03.00, CENTUM VP Small R4.01.0 OS command injection vulnerability exists in CENTUM VP R4.01.00 to R4.03.00, CENTUM VP Small R4.01.00 to R4.03.00, CENTUM VP Basic R4.01.00 to R4.03.00, and B/M9000 VP R6.01.01 to R6.03.02, which may allow an attacker who can access the computer where the affected product is installed to execute an arbitrary OS command by altering a file generated usin
nvd
CVE-2023-26593P3HIGHCVSS 7.8≥ r4.01.00, ≤ r4.03.00≥ r5.01.00, ≤ r5.04.20+1 more2023-04-11
CVE-2023-26593 [HIGH] CWE-312 CVE-2023-26593: CENTUM series provided by Yokogawa Electric Corporation are vulnerable to cleartext storage of sensi CENTUM series provided by Yokogawa Electric Corporation are vulnerable to cleartext storage of sensitive information. If an attacker who can login or access the computer where the affected product is installed tampers the password file stored in the computer, the user privilege which CENTUM managed may be escalated. As a result, the control system may
nvd
CVE-2018-8838P4MEDIUMCVSS 6.5≤ r6.03.102018-04-17
CVE-2018-8838 [MEDIUM] CVE-2018-8838: A weakness in access controls in CENTUM CS 1000 all versions, CENTUM CS 3000 versions R3.09.50 and e A weakness in access controls in CENTUM CS 1000 all versions, CENTUM CS 3000 versions R3.09.50 and earlier, CENTUM CS 3000 Small versions R3.09.50 and earlier, CENTUM VP versions R6.03.10 and earlier, CENTUM VP Small versions R6.03.10 and earlier, CENTUM VP Basic versions R6.03.10 and earlier, Exaopc versions R3.75.00 and earlier, B/M9000 CS all versions, and
nvd
Yokogawa Centum Vp vulnerabilities | cvebase