CVE-2022-33939
If this vulnerability is exploited, an attacker may cause a denial of service (DoS) condition in ADL communication by sending a specially crafted packet to the affected product.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.17%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
CENTUM VP / CS 3000 controller FCS (CP31, CP33, CP345, CP401, and CP451) contains an issue in processing communication packets, which may lead to resource consumption. If this vulnerability is exploited, an attacker may cause a denial of service (DoS) condition in ADL communication by sending a specially crafted packet to the affected product.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.17% probability · 66th percentile
- CISA KEV
- Not listed
- Affected
- yokogawa/centum cs 3000 cp401 firmware · yokogawa/centum cs 3000 cp451 firmware · yokogawa/centum cs 3000 cp33 firmware · yokogawa/centum cs 3000 cp345 firmware · yokogawa/centum cs 3000 cp31 firmware · yokogawa/centum vp 3000 cp401 firmware · yokogawa/centum vp 3000 cp451 firmware
- Source
- vultures@jpcert.or.jp
References
- https://jvn.jp/vu/JVNVU94343729/index.htmlThird Party Advisory
- https://web-material3.yokogawa.com/1/33029/files/YSAR-22-0008-E.pdfVendor Advisory
- https://web-material3.yokogawa.com/19/33029/files/YSAR-22-0008-J.pdfVendor Advisory
- https://jvn.jp/vu/JVNVU94343729/index.htmlThird Party Advisory
- https://web-material3.yokogawa.com/1/33029/files/YSAR-22-0008-E.pdfVendor Advisory
- https://web-material3.yokogawa.com/19/33029/files/YSAR-22-0008-J.pdfVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.