CVE-2022-33939
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
CENTUM VP / CS 3000 controller FCS (CP31, CP33, CP345, CP401, and CP451) contains an issue in processing communication packets, which may lead to resource consumption. If this vulnerability is exploited, an attacker may cause a denial of service (DoS) condition in ADL communication by sending a specially crafted packet to the affected product.
Affected (11)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Yokogawa Centum Cs 3000 Cp401 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Yokogawa Centum Cs 3000 Cp451 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Yokogawa Centum Cs 3000 Cp33 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Yokogawa Centum Cs 3000 Cp345 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Yokogawa Centum Cs 3000 Cp31 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From r4.01.00 to r4.03.00 |
| Running on/with | Platform Versions |
|---|---|
Yokogawa Centum Vp 3000 Cp401 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From r4.01.00 to r4.03.00 |
| Running on/with | Platform Versions |
|---|---|
Yokogawa Centum Vp 3000 Cp451 | All versions |
References (6)
Source: vultures@jpcert.or.jp
Vendor Advisory
Source: vultures@jpcert.or.jp
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.