CVE-2018-16196
Multiple Yokogawa products that contain Vnet/IP Open Communication Driver (CENTUM CS 3000(R3.05.00 - R3.09.50), CENTUM CS 3000 Entry Class(R3.05.00 - R3.09.50), CENTUM VP(R4.01.00 - R6.03.10), CENTUM VP Entry Class(R4.01.00 - R6.03.10), Exaopc(R3.10.00…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.34%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple Yokogawa products that contain Vnet/IP Open Communication Driver (CENTUM CS 3000(R3.05.00 - R3.09.50), CENTUM CS 3000 Entry Class(R3.05.00 - R3.09.50), CENTUM VP(R4.01.00 - R6.03.10), CENTUM VP Entry Class(R4.01.00 - R6.03.10), Exaopc(R3.10.00 - R3.75.00), PRM(R2.06.00 - R3.31.00), ProSafe-RS(R1.02.00 - R4.02.00), FAST/TOOLS(R9.02.00 - R10.02.00), B/M9000 VP(R6.03.01 - R8.01.90)) allows remote attackers to cause a denial of service attack that may result in stopping Vnet/IP Open Communication Driver's communication via unspecified vectors.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 3.34% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- yokogawa/centum cs 3000 firmware · yokogawa/centum cs 3000 entry class · yokogawa/centum vp firmware · yokogawa/centum vp entry class · yokogawa/b\/m9000 vp · yokogawa/exaopc · yokogawa/fast\/tools · yokogawa/plant resource manager · yokogawa/prosafe-rs
- Source
- vultures@jpcert.or.jp
References
- http://www.securityfocus.com/bid/106442Third Party Advisory, VDB Entry
- https://jvn.jp/vu/JVNVU93652047/index.htmlThird Party Advisory, VDB Entry
- https://web-material3.yokogawa.com/YSAR-18-0008-E.pdfVendor Advisory
- http://www.securityfocus.com/bid/106442Third Party Advisory, VDB Entry
- https://jvn.jp/vu/JVNVU93652047/index.htmlThird Party Advisory, VDB Entry
- https://web-material3.yokogawa.com/YSAR-18-0008-E.pdfVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.