CVE-2022-22148
Summary
| CVE | CVE-2022-22148 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-11 09:15:00 UTC |
| Updated | 2022-03-18 15:17:00 UTC |
| Description | 'Root Service' service implemented in the following Yokogawa Electric products creates some named pipe with improper ACL configuration. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00. |
Risk And Classification
Problem Types: CWE-732
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Yokogawa | Centum Cs 3000 | - | All | All | All |
| Hardware | Yokogawa | Centum Cs 3000 Entry | - | All | All | All |
| Operating System | Yokogawa | Centum Cs 3000 Entry Firmware | All | All | All | All |
| Operating System | Yokogawa | Centum Cs 3000 Firmware | All | All | All | All |
| Hardware | Yokogawa | Centum Vp | - | All | All | All |
| Hardware | Yokogawa | Centum Vp Entry | - | All | All | All |
| Operating System | Yokogawa | Centum Vp Entry Firmware | All | All | All | All |
| Operating System | Yokogawa | Centum Vp Entry Firmware | All | All | All | All |
| Operating System | Yokogawa | Centum Vp Entry Firmware | All | All | All | All |
| Operating System | Yokogawa | Centum Vp Firmware | All | All | All | All |
| Operating System | Yokogawa | Centum Vp Firmware | All | All | All | All |
| Operating System | Yokogawa | Centum Vp Firmware | All | All | All | All |
| Application | Yokogawa | Exaopc | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| web-material3.yokogawa.com/1/32094/files/YSAR-22-0001-E.pdf | CONFIRM | web-material3.yokogawa.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590868 Yokogawa CENTUM Multiple Vulnerabilities (ICSA-22-083-01) (YSAR-22-0001)