CVE-2018-17896
Published on: 10/12/2018 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:24:19 PM UTC
Certain versions of Fcj from Yokogawa contain the following vulnerability:
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credentials which may allow an attacker gain unauthorized access to the maintenance functions and obtain or modify information. This attack can be executed only during maintenance work.
- CVE-2018-17896 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Yokogawa - STARDOM Controllers FCJ,FCN-100,FCN-RTU, FCN-500 version All versions prior to version X.X
CVSS3 Score: 8.1 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | HIGH | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 9.3 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
COMPLETE | COMPLETE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Yokogawa STARDOM Controllers (Update A) | ICS-CERT | Third Party Advisory US Government Resource ics-cert.us-cert.gov text/html |
![]() |
Vendor Advisory web-material3.yokogawa.com application/pdf |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Yokogawa | Fcj | - | All | All | All |
Hardware
| Yokogawa | Fcj | - | All | All | All |
Operating System | Yokogawa | Fcj Firmware | All | All | All | All |
Hardware
| Yokogawa | Fcn-100 | - | All | All | All |
Hardware
| Yokogawa | Fcn-100 | - | All | All | All |
Operating System | Yokogawa | Fcn-100 Firmware | All | All | All | All |
Hardware
| Yokogawa | Fcn-500 | - | All | All | All |
Hardware
| Yokogawa | Fcn-500 | - | All | All | All |
Operating System | Yokogawa | Fcn-500 Firmware | All | All | All | All |
Hardware
| Yokogawa | Fcn-rtu | - | All | All | All |
Hardware
| Yokogawa | Fcn-rtu | - | All | All | All |
Operating System | Yokogawa | Fcn-rtu Firmware | All | All | All | All |
- cpe:2.3:h:yokogawa:fcj:-:*:*:*:*:*:*:*:
- cpe:2.3:h:yokogawa:fcj:-:*:*:*:*:*:*:*:
- cpe:2.3:o:yokogawa:fcj_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:yokogawa:fcn-100:-:*:*:*:*:*:*:*:
- cpe:2.3:h:yokogawa:fcn-100:-:*:*:*:*:*:*:*:
- cpe:2.3:o:yokogawa:fcn-100_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:yokogawa:fcn-500:-:*:*:*:*:*:*:*:
- cpe:2.3:h:yokogawa:fcn-500:-:*:*:*:*:*:*:*:
- cpe:2.3:o:yokogawa:fcn-500_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:yokogawa:fcn-rtu:-:*:*:*:*:*:*:*:
- cpe:2.3:h:yokogawa:fcn-rtu:-:*:*:*:*:*:*:*:
- cpe:2.3:o:yokogawa:fcn-rtu_firmware:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE