SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-3888

Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM VP R5.03.20 and earlier, Exaopc R3.72.00 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier, when…

HIGH 8.3EPSS 62.3%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 62.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM VP R5.03.20 and earlier, Exaopc R3.72.00 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier, when FCS/Test Function is enabled, allows remote attackers to execute arbitrary code via a crafted packet.

CVSS 2.0
8.3 HIGHAV:N/AC:M/Au:N/C:P/I:P/A:C
EPSS
62.31% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
yokogawa/exaopc · yokogawa/b\/m9000cs software · yokogawa/b\/m9000cs · yokogawa/centum vp entry class software · yokogawa/centum vp entry class · yokogawa/centum vp software · yokogawa/centum vp · yokogawa/b\/m9000 vp software · yokogawa/b\/m9000 vp · yokogawa/centum cs 3000 software · yokogawa/centum cs 3000 · yokogawa/centum cs 1000 software · yokogawa/centum cs 1000 · yokogawa/centum cs 3000 entry class software · yokogawa/centum cs 3000 entry class
Source
vultures@jpcert.or.jp

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.