CVE-2020-5608
Published on: 08/05/2020 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:24:03 PM UTC
Certain versions of B/m9000cs from Yokogawa contain the following vulnerability:
CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B/M9000CS R5.04.01 to R5.05.01, and B/M9000 VP R6.01.01 to R8.03.01 allows a remote unauthenticated attacker to bypass authentication and send altered communication packets via unspecified vectors.
- CVE-2020-5608 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
- Affected Vendor/Software:
Yokogawa Electric Corporation - CAMS for HIS version CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B/M9000CS R5.04.01 to R5.05.01, and B/M9000 VP R6.01.01 to R8.03.01
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 7.5 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
JVNVU#97997181: 横河電機製 CAMS for HIS に複数の脆弱性 | Third Party Advisory jvn.jp text/xml |
![]() |
Vendor Advisory web-material3.yokogawa.com application/pdf |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Yokogawa | B/m9000cs | - | All | All | All |
Hardware
| Yokogawa | B/m9000cs | - | All | All | All |
Operating System | Yokogawa | B/m9000cs Firmware | All | All | All | All |
Hardware
| Yokogawa | B/m9000vp | - | All | All | All |
Hardware
| Yokogawa | B/m9000vp | - | All | All | All |
Operating System | Yokogawa | B/m9000vp Firmware | All | All | All | All |
Hardware
| Yokogawa | Centum Cs 3000 | - | All | All | All |
Hardware
| Yokogawa | Centum Cs 3000 | - | All | All | All |
Operating System | Yokogawa | Centum Cs 3000 Firmware | All | All | All | All |
Hardware
| Yokogawa | Centum Vp | - | All | All | All |
Hardware
| Yokogawa | Centum Vp | - | All | All | All |
Operating System | Yokogawa | Centum Vp Firmware | All | All | All | All |
Operating System | Yokogawa | Centum Vp Firmware | All | All | All | All |
Operating System | Yokogawa | Centum Vp Firmware | All | All | All | All |
- cpe:2.3:h:yokogawa:b\/m9000cs:-:*:*:*:*:*:*:*:
- cpe:2.3:h:yokogawa:b\/m9000cs:-:*:*:*:*:*:*:*:
- cpe:2.3:o:yokogawa:b\/m9000cs_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:yokogawa:b\/m9000vp:-:*:*:*:*:*:*:*:
- cpe:2.3:h:yokogawa:b\/m9000vp:-:*:*:*:*:*:*:*:
- cpe:2.3:o:yokogawa:b\/m9000vp_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:yokogawa:centum_cs_3000:-:*:*:*:*:*:*:*:
- cpe:2.3:h:yokogawa:centum_cs_3000:-:*:*:*:*:*:*:*:
- cpe:2.3:o:yokogawa:centum_cs_3000_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:yokogawa:centum_vp:-:*:*:*:*:*:*:*:
- cpe:2.3:h:yokogawa:centum_vp:-:*:*:*:*:*:*:*:
- cpe:2.3:o:yokogawa:centum_vp_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:yokogawa:centum_vp_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:yokogawa:centum_vp_firmware:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE