CVE-2014-3888
Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM VP R5.03.20 and earlier, Exaopc R3.72.00 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier, when…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 62.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM VP R5.03.20 and earlier, Exaopc R3.72.00 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier, when FCS/Test Function is enabled, allows remote attackers to execute arbitrary code via a crafted packet.
- CVSS 2.0
- 8.3 HIGHAV:N/AC:M/Au:N/C:P/I:P/A:C
- EPSS
- 62.31% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- yokogawa/exaopc · yokogawa/b\/m9000cs software · yokogawa/b\/m9000cs · yokogawa/centum vp entry class software · yokogawa/centum vp entry class · yokogawa/centum vp software · yokogawa/centum vp · yokogawa/b\/m9000 vp software · yokogawa/b\/m9000 vp · yokogawa/centum cs 3000 software · yokogawa/centum cs 3000 · yokogawa/centum cs 1000 software · yokogawa/centum cs 1000 · yokogawa/centum cs 3000 entry class software · yokogawa/centum cs 3000 entry class
- Source
- vultures@jpcert.or.jp
References
- http://ics-cert.us-cert.gov/advisories/ICSA-14-189-01Third Party Advisory, US Government Resource
- http://osvdb.org/show/osvdb/108756
- http://packetstormsecurity.com/files/127382/Yokogawa-CS3000-BKFSim_vhfd.exe-Buffer-Overflow.htmlExploit
- http://www.exploit-db.com/exploits/34009
- http://www.yokogawa.com/dcs/security/ysar/YSAR-14-0002E.pdfVendor Advisory
- http://ics-cert.us-cert.gov/advisories/ICSA-14-189-01Third Party Advisory, US Government Resource
- http://osvdb.org/show/osvdb/108756
- http://packetstormsecurity.com/files/127382/Yokogawa-CS3000-BKFSim_vhfd.exe-Buffer-Overflow.htmlExploit
- http://www.exploit-db.com/exploits/34009
- http://www.yokogawa.com/dcs/security/ysar/YSAR-14-0002E.pdfVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.