VYPR
Unrated severityNVD Advisory· Published Mar 11, 2022· Updated Aug 3, 2024

CVE-2022-22729

CVE-2022-22729

Description

CAMS for HIS Server contained in the following Yokogawa Electric products improperly authenticate the receiving packets. The authentication may be bypassed via some crafted packets: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, and Exaopc versions from R3.72.00 to R3.79.00.

Affected products

6
  • Yokogawa/Exaopcllm-fuzzy
    Range: R3.72.00 to R3.79.00
  • Range: R3.08.10 to R3.09.00
  • Range: R4.01.00 to R4.03.00, R5.01.00 to R5.04.20, R6.01.00 to R6.08.00
  • Yokogawa Electric Corporation/CENTUM CS 3000v5
    Range: versions from R3.08.10 to R3.09.00
  • Yokogawa Electric Corporation/CENTUM VPv5
    Range: versions from R4.01.00 to R4.03.00
  • Yokogawa Electric Corporation/Exaopcv5
    Range: versions from R3.72.00 to R3.79.00

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.