Vulnerabilities > Yokogawa

DATE CVE VULNERABILITY TITLE RISK
2018-10-12 CVE-2018-17902 Session Fixation vulnerability in Yokogawa products
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The application utilizes multiple methods of session management which could result in a denial of service to the remote management functions.
network
low complexity
yokogawa CWE-384
5.0
2018-10-12 CVE-2018-17900 Insufficiently Protected Credentials vulnerability in Yokogawa products
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which could allow an attacker to obtain credentials for remote access to controllers.
network
low complexity
yokogawa CWE-522
5.0
2018-10-12 CVE-2018-17898 Resource Exhaustion vulnerability in Yokogawa products
Yokogawa STARDOM Controllers FCJ,FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The controller application fails to prevent memory exhaustion by unauthorized requests.
network
low complexity
yokogawa CWE-400
7.8
2018-10-12 CVE-2018-17896 Use of Hard-coded Credentials vulnerability in Yokogawa products
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credentials which may allow an attacker gain unauthorized access to the maintenance functions and obtain or modify information.
network
yokogawa CWE-798
critical
9.3
2018-07-31 CVE-2018-10592 Use of Hard-coded Credentials vulnerability in Yokogawa products
Yokogawa STARDOM FCJ controllers R4.02 and prior, FCN-100 controllers R4.02 and prior, FCN-RTU controllers R4.02 and prior, and FCN-500 controllers R4.02 and prior utilize hard-coded credentials that could allow an attacker to gain unauthorized administrative access to the device, which could result in remote code execution.
network
low complexity
yokogawa CWE-798
critical
10.0
2018-04-17 CVE-2018-8838 Unspecified vulnerability in Yokogawa products
A weakness in access controls in CENTUM CS 1000 all versions, CENTUM CS 3000 versions R3.09.50 and earlier, CENTUM CS 3000 Small versions R3.09.50 and earlier, CENTUM VP versions R6.03.10 and earlier, CENTUM VP Small versions R6.03.10 and earlier, CENTUM VP Basic versions R6.03.10 and earlier, Exaopc versions R3.75.00 and earlier, B/M9000 CS all versions, and B/M9000 VP versions R8.01.01 and earlier may allow a local attacker to exploit the message management function of the system.
local
yokogawa
4.4
2016-09-19 CVE-2016-4860 Improper Authentication vulnerability in Yokogawa Stardom Fcn/Fcj
Yokogawa STARDOM FCN/FCJ controller R1.01 through R4.01 does not require authentication for Logic Designer connections, which allows remote attackers to reconfigure the device or cause a denial of service via a (1) stop application program, (2) change value, or (3) modify application command.
network
low complexity
yokogawa CWE-287
7.5
2014-12-22 CVE-2014-5208 Improper Access Control vulnerability in Yokogawa Centum CS 3000, Centum VP and Exaopc
BKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM VP through R4.03.00 and R5.x through R5.04.00, and Exaopc through R3.72.10, does not require authentication, which allows remote attackers to read arbitrary files via a RETR operation, write to arbitrary files via a STOR operation, or obtain sensitive database-location information via a PMODE operation, a different vulnerability than CVE-2014-0784.
network
low complexity
yokogawa CWE-284
7.5
2014-12-06 CVE-2014-7251 Improper Input Validation vulnerability in Yokogawa Fast/Tools
XML external entity (XXE) vulnerability in the WebHMI server in Yokogawa Electric Corporation FAST/TOOLS before R9.05-SP2 allows local users to cause a denial of service (CPU or network traffic consumption) or read arbitrary files via unspecified vectors.
local
low complexity
yokogawa CWE-20
3.2
2014-07-10 CVE-2014-3888 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Yokogawa products
Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM VP R5.03.20 and earlier, Exaopc R3.72.00 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier, when FCS/Test Function is enabled, allows remote attackers to execute arbitrary code via a crafted packet.
network
yokogawa CWE-119
8.3