← Back

CVE-2022-22141

nvd nist
Published: Mar 11, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

'Long-term Data Archive Package' service implemented in the following Yokogawa Electric products creates some named pipe with imporper ACL configuration. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00.

Affected (9)

5 products
Centum Cs 3000 Firmware
Centum Cs 3000 Entry Firmware
Centum Vp Firmware
Centum Vp Entry Firmware
Exaopc
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From r3.08.10 to r3.09.00
Running on/withPlatform Versions
Yokogawa
Centum Cs 3000
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From r3.08.10 to r3.09.00
Running on/withPlatform Versions
Yokogawa
Centum Cs 3000 Entry
All versions
Configuration C
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Yokogawa
From r4.01.00 to r4.03.00
From r5.01.00 to r5.04.20
From r6.01.00 to r6.09.00
Running on/withPlatform Versions
Yokogawa
Centum Vp
All versions
Configuration D
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Yokogawa
From r4.01.00 to r4.03.00
From r5.01.00 to r5.04.20
From r6.01.00 to r6.09.00
Running on/withPlatform Versions
Yokogawa
Centum Vp Entry
All versions
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
From r3.72.00 to r3.80.00

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.