CVE-2014-0782
Stack-based buffer overflow in BKESimmgr.exe in the Expanded Test Functions package in Yokogawa CENTUM CS 1000, CENTUM CS 3000 Entry Class R3.09.50 and earlier, CENTUM VP R5.03.00 and earlier, CENTUM VP Entry Class R5.03.00 and earlier, Exaopc R3.71.02…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 56.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Stack-based buffer overflow in BKESimmgr.exe in the Expanded Test Functions package in Yokogawa CENTUM CS 1000, CENTUM CS 3000 Entry Class R3.09.50 and earlier, CENTUM VP R5.03.00 and earlier, CENTUM VP Entry Class R5.03.00 and earlier, Exaopc R3.71.02 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier allows remote attackers to execute arbitrary code via a crafted packet.
- CVSS 2.0
- 8.3 HIGHAV:N/AC:M/Au:N/C:P/I:P/A:C
- EPSS
- 56.84% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-121, CWE-119
- Affected
- yokogawa/b\/m9000cs software · yokogawa/b\/m9000cs · yokogawa/centum cs 1000 software · yokogawa/centum cs 1000 · yokogawa/centum cs 3000 software · yokogawa/centum cs 3000 · yokogawa/centum cs 3000 entry class software · yokogawa/centum cs 3000 entry class · yokogawa/exaopc · yokogawa/b\/m9000 vp software · yokogawa/b\/m9000 vp · yokogawa/centum vp entry class software · yokogawa/centum vp entry class · yokogawa/centum vp software · yokogawa/centum vp
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/66130
- http://www.yokogawa.com/dcs/security/ysar/dcs-ysar-index-en.htm.
- https://community.rapid7.com/community/metasploit/blog/2014/03/10/yokogawa-centum-cs3000-vulnerabilities
- https://www.cisa.gov/news-events/ics-advisories/icsa-14-070-01a
- http://ics-cert.us-cert.gov/advisories/ICSA-14-133-01US Government Resource
- http://www.yokogawa.com/dcs/security/ysar/YSAR-14-0001E.pdfVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.