SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-0651

Buffer overflow in the license management function of YOKOGAWA products (iDefine for ProSafe-RS R1.16.3 and earlier, STARDOM VDS R7.50 and earlier, STARDOM FCN/FCJ Simulator R4.20 and earlier, ASTPLANNER R15.01 and earlier, TriFellows V5.04 and earlier)…

CRITICAL 9.8EPSS 3.97%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (3.97%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Buffer overflow in the license management function of YOKOGAWA products (iDefine for ProSafe-RS R1.16.3 and earlier, STARDOM VDS R7.50 and earlier, STARDOM FCN/FCJ Simulator R4.20 and earlier, ASTPLANNER R15.01 and earlier, TriFellows V5.04 and earlier) allows remote attackers to stop the license management function or execute an arbitrary program via unspecified vectors.

CVSS 3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
3.97% probability · 90th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
yokogawa/idefine for prosafe-rs firmware · yokogawa/stardom versatile data server firmware · yokogawa/stardom fcn\/fcj simulator firmware · yokogawa/astplanner · yokogawa/trifellows
Source
vultures@jpcert.or.jp

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.