CVE-2014-3888
8.3
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:C
Exploitability: 8.6 / Impact: 8.5
Source: NVD
Description
Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM VP R5.03.20 and earlier, Exaopc R3.72.00 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier, when FCS/Test Function is enabled, allows remote attackers to execute arbitrary code via a crafted packet.
Affected (17)
Products: Yokogawa: Exaopc, B/m9000cs Software, B/m9000cs, Centum Vp Entry Class Software, Centum Vp Entry Class, Centum Vp Software, Centum Vp, B/m9000 Vp Software, B/m9000 Vp, Centum Cs 3000 Software, Centum Cs 3000, Centum Cs 1000 Software, Centum Cs 1000, Centum Cs 3000 Entry Class Software, Centum Cs 3000 Entry Class
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.05.01 | |
| All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.03.00 | |
| All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.03.20 | |
| All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 7.03.01 | |
| All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.23.00 | |
| All versions |
| Running on/with | Platform Versions |
|---|---|
Yokogawa Centum Cs 3000 | Version r3.01 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.09.50 | |
| All versions |
References (10)
Source: vultures@jpcert.or.jp
Third Party AdvisoryUS Government Resource
Source: vultures@jpcert.or.jp
Source: vultures@jpcert.or.jp
Exploit
Source: vultures@jpcert.or.jp
Source: vultures@jpcert.or.jp
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.