CVE-2022-22148
Published on: Not Yet Published
Last Modified on: 03/18/2022 03:17:00 PM UTC
Certain versions of Centum Cs 3000 from Yokogawa contain the following vulnerability:
'Root Service' service implemented in the following Yokogawa Electric products creates some named pipe with improper ACL configuration. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00.
- CVE-2022-22148 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Yokogawa Electric Corporation - CENTUM CS 3000 version versions from R3.08.10 to R3.09.00
- Affected Vendor/Software:
Yokogawa Electric Corporation - CENTUM VP version versions from R4.01.00 to R4.03.00
- Affected Vendor/Software:
Yokogawa Electric Corporation - CENTUM VP version versions from R5.01.00 to R5.04.20
- Affected Vendor/Software:
Yokogawa Electric Corporation - CENTUM VP version versions from R6.01.00 to R6.08.00
- Affected Vendor/Software:
Yokogawa Electric Corporation - Exaopc version versions from R3.72.00 to R3.79.00
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 6.9 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
LOCAL | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
COMPLETE | COMPLETE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
web-material3.yokogawa.com application/pdf |
![]() |
Related QID Numbers
- 590868 Yokogawa CENTUM Multiple Vulnerabilities (ICSA-22-083-01) (YSAR-22-0001)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Yokogawa | Centum Cs 3000 | - | All | All | All |
Hardware
| Yokogawa | Centum Cs 3000 Entry | - | All | All | All |
Operating System | Yokogawa | Centum Cs 3000 Entry Firmware | All | All | All | All |
Operating System | Yokogawa | Centum Cs 3000 Firmware | All | All | All | All |
Hardware
| Yokogawa | Centum Vp | - | All | All | All |
Hardware
| Yokogawa | Centum Vp Entry | - | All | All | All |
Operating System | Yokogawa | Centum Vp Entry Firmware | All | All | All | All |
Operating System | Yokogawa | Centum Vp Entry Firmware | All | All | All | All |
Operating System | Yokogawa | Centum Vp Entry Firmware | All | All | All | All |
Operating System | Yokogawa | Centum Vp Firmware | All | All | All | All |
Operating System | Yokogawa | Centum Vp Firmware | All | All | All | All |
Operating System | Yokogawa | Centum Vp Firmware | All | All | All | All |
Application | Yokogawa | Exaopc | All | All | All | All |
- cpe:2.3:h:yokogawa:centum_cs_3000:-:*:*:*:*:*:*:*:
- cpe:2.3:h:yokogawa:centum_cs_3000_entry:-:*:*:*:*:*:*:*:
- cpe:2.3:o:yokogawa:centum_cs_3000_entry_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:yokogawa:centum_cs_3000_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:yokogawa:centum_vp:-:*:*:*:*:*:*:*:
- cpe:2.3:h:yokogawa:centum_vp_entry:-:*:*:*:*:*:*:*:
- cpe:2.3:o:yokogawa:centum_vp_entry_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:yokogawa:centum_vp_entry_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:yokogawa:centum_vp_entry_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:yokogawa:centum_vp_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:yokogawa:centum_vp_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:yokogawa:centum_vp_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:a:yokogawa:exaopc:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-22148 : 'Root Service' service implemented in the following Yokogawa Electric products creates some named… twitter.com/i/web/status/1… | 2022-03-11 09:18:35 |
![]() |
CVE-2022-22148 | 2022-03-11 10:38:21 |