SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-0782

Stack-based buffer overflow in BKESimmgr.exe in the Expanded Test Functions package in Yokogawa CENTUM CS 1000, CENTUM CS 3000 Entry Class R3.09.50 and earlier, CENTUM VP R5.03.00 and earlier, CENTUM VP Entry Class R5.03.00 and earlier, Exaopc R3.71.02…

HIGH 8.3EPSS 56.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 56.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Stack-based buffer overflow in BKESimmgr.exe in the Expanded Test Functions package in Yokogawa CENTUM CS 1000, CENTUM CS 3000 Entry Class R3.09.50 and earlier, CENTUM VP R5.03.00 and earlier, CENTUM VP Entry Class R5.03.00 and earlier, Exaopc R3.71.02 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier allows remote attackers to execute arbitrary code via a crafted packet.

CVSS 2.0
8.3 HIGHAV:N/AC:M/Au:N/C:P/I:P/A:C
EPSS
56.84% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-121, CWE-119
Affected
yokogawa/b\/m9000cs software · yokogawa/b\/m9000cs · yokogawa/centum cs 1000 software · yokogawa/centum cs 1000 · yokogawa/centum cs 3000 software · yokogawa/centum cs 3000 · yokogawa/centum cs 3000 entry class software · yokogawa/centum cs 3000 entry class · yokogawa/exaopc · yokogawa/b\/m9000 vp software · yokogawa/b\/m9000 vp · yokogawa/centum vp entry class software · yokogawa/centum vp entry class · yokogawa/centum vp software · yokogawa/centum vp
Source
ics-cert@hq.dhs.gov

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.