SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-33939

If this vulnerability is exploited, an attacker may cause a denial of service (DoS) condition in ADL communication by sending a specially crafted packet to the affected product.

HIGH 7.5EPSS 1.17%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.17%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

CENTUM VP / CS 3000 controller FCS (CP31, CP33, CP345, CP401, and CP451) contains an issue in processing communication packets, which may lead to resource consumption. If this vulnerability is exploited, an attacker may cause a denial of service (DoS) condition in ADL communication by sending a specially crafted packet to the affected product.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
1.17% probability · 66th percentile
CISA KEV
Not listed
Affected
yokogawa/centum cs 3000 cp401 firmware · yokogawa/centum cs 3000 cp451 firmware · yokogawa/centum cs 3000 cp33 firmware · yokogawa/centum cs 3000 cp345 firmware · yokogawa/centum cs 3000 cp31 firmware · yokogawa/centum vp 3000 cp401 firmware · yokogawa/centum vp 3000 cp451 firmware
Source
vultures@jpcert.or.jp

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.