High severity8.8NVD Advisory· Published Mar 11, 2022· Updated Jun 17, 2026
CVE-2022-22729
CVE-2022-22729
Description
CAMS for HIS Server contained in the following Yokogawa Electric products improperly authenticate the receiving packets. The authentication may be bypassed via some crafted packets: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, and Exaopc versions from R3.72.00 to R3.79.00.
Affected products
12- cpe:2.3:o:yokogawa:centum_cs_3000_entry_firmware:*:*:*:*:*:*:*:*Range: >=r3.08.10,<=r3.09.00
- cpe:2.3:o:yokogawa:centum_cs_3000_firmware:*:*:*:*:*:*:*:*Range: >=r3.08.10,<=r3.09.00
- cpe:2.3:o:yokogawa:centum_vp_entry_firmware:*:*:*:*:*:*:*:*Range: >=r4.01.00,<=r4.03.00
- cpe:2.3:o:yokogawa:centum_vp_firmware:*:*:*:*:*:*:*:*Range: >=r4.01.00,<=r4.03.00
- Range: R3.08.10 - R3.09.00
- Yokogawa Electric Corporation/CENTUM CS 3000v5Range: versions from R3.08.10 to R3.09.00
- Yokogawa Electric Corporation/CENTUM VPv5Range: versions from R4.01.00 to R4.03.00
- Yokogawa Electric Corporation/Exaopcv5Range: versions from R3.72.00 to R3.79.00
Patches
Vulnerability mechanics
References
1- web-material3.yokogawa.com/1/32094/files/YSAR-22-0001-E.pdfnvdMitigationVendor Advisory
News mentions
0No linked articles in our index yet.