VYPR
High severity8.8NVD Advisory· Published Mar 11, 2022· Updated Jun 17, 2026

CVE-2022-22729

CVE-2022-22729

Description

CAMS for HIS Server contained in the following Yokogawa Electric products improperly authenticate the receiving packets. The authentication may be bypassed via some crafted packets: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, and Exaopc versions from R3.72.00 to R3.79.00.

Affected products

12
  • cpe:2.3:o:yokogawa:centum_cs_3000_firmware:*:*:*:*:*:*:*:*
    Range: >=r3.08.10,<=r3.09.00
  • cpe:2.3:o:yokogawa:centum_cs_3000_entry_firmware:*:*:*:*:*:*:*:*
    Range: >=r3.08.10,<=r3.09.00
  • cpe:2.3:o:yokogawa:centum_vp_firmware:*:*:*:*:*:*:*:*
    Range: >=r4.01.00,<=r4.03.00
  • cpe:2.3:o:yokogawa:centum_vp_entry_firmware:*:*:*:*:*:*:*:*
    Range: >=r4.01.00,<=r4.03.00
  • Yokogawa/Exaopc3 versions
    cpe:2.3:a:yokogawa:exaopc:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:yokogawa:exaopc:*:*:*:*:*:*:*:*range: >=r3.72.00,<r3.80.00
    • (no CPE)range: versions from R3.72.00 to R3.79.00
    • (no CPE)range: R3.72.00 - R3.79.00
  • Yokogawa/Centum Cs 3000cpe-rescue2 versions
    versions from R3.08.10 to R3.09.00+ 1 more
    • (no CPE)range: versions from R3.08.10 to R3.09.00
    • (no CPE)range: R3.08.10 - R3.09.00
  • Yokogawa/CENTUM VPcpe-rescue2 versions
    versions from R4.01.00 to R4.03.00+ 1 more
    • (no CPE)range: versions from R4.01.00 to R4.03.00
    • (no CPE)range: R4.01.00 - R4.03.00, R5.01.00 - R5.04.20, R6.01.00 - R6.08.00

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.