VYPR

Vendor CVEs

Yokogawa

All CVEs

72 total · sorted by risk
  • CVE-2025-48019MedFeb 13, 2026
    risk 0.42cvss 6.5epss 0.00

    A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciously crafted packets, Vnet/IP software stack process may be terminated. The affected products and versions are as follows: Vnet/IP Interface…

  • CVE-2018-8838MedApr 17, 2018
    risk 0.42cvss 6.5epss 0.00

    A weakness in access controls in CENTUM CS 1000 all versions, CENTUM CS 3000 versions R3.09.50 and earlier, CENTUM CS 3000 Small versions R3.09.50 and earlier, CENTUM VP versions R6.03.10 and earlier, CENTUM VP Small versions R6.03.10 and earlier, CENTUM VP Basic versions…

  • CVE-2025-66596MedFeb 9, 2026
    risk 0.40cvss 6.1epss 0.00

    A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly validate request headers. When an attacker inserts an invalid host header, users could be redirected to malicious sites. The affected products and…

  • CVE-2025-66601MedFeb 9, 2026
    risk 0.40cvss 6.1epss 0.00

    A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not specify MIME types. When an attacker performs a content sniffing attack, malicious scripts could be executed. The affected products and versions are as follows:…

  • CVE-2024-4105MedJun 26, 2024
    risk 0.38cvss 5.8epss 0.00

    A vulnerability has been found in FAST/TOOLS and CI Server. The affected product's WEB HMI server's function to process HTTP requests has a security flaw (Reflected XSS) that allows the execution of malicious scripts. Therefore, if a client PC with inadequate security measures…

  • CVE-2025-66595MedFeb 9, 2026
    risk 0.35cvss 5.4epss 0.00

    A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product is vulnerable to Cross-Site Request Forgery (CSRF). When a user accesses a link crafted by an attacker, the user’s account could be compromised. The affected products and…

  • CVE-2023-5915MedDec 1, 2023
    risk 0.35cvss 5.3epss 0.01

    A vulnerability of Uncontrolled Resource Consumption has been identified in STARDOM provided by Yokogawa Electric Corporation. This vulnerability may allow to a remote attacker to cause a denial-of-service condition to the FCN/FCJ controller by sending a crafted packet. While…

  • CVE-2018-17902MedOct 12, 2018
    risk 0.35cvss 5.3epss 0.01

    Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The application utilizes multiple methods of session management which could result in a denial of service to the remote management functions.

  • CVE-2025-66594MedFeb 9, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Detailed messages are displayed on the error page. This information could be exploited by an attacker for other attacks. The affected products and versions are as follows: FAST/TOOLS…

  • CVE-2025-66607MedFeb 9, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The response header contains an insecure setting. Users could be redirected to malicious sites by an attacker. The affected products and versions are as follows: FAST/TOOLS (Packages:…

  • CVE-2025-66605MedFeb 9, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Since there are input fields on this webpage with the autocomplete attribute enabled, the input content could be saved in the browser the user is using. The affected products and…

  • CVE-2025-66604MedFeb 9, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The library version could be displayed on the web page. This information could be exploited by an attacker for other attacks. The affected products and versions are as follows:…

  • CVE-2024-4106MedJun 26, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in FAST/TOOLS and CI Server. The affected products have built-in accounts with no passwords set. Therefore, if the product is operated without a password set by default, an attacker can break into the affected product. The affected products and…

  • CVE-2020-16232LowMar 18, 2022
    risk 0.18cvss 2.8epss 0.01

    In Yokogawa WideField3 R1.01 - R4.03, a buffer overflow could be caused when a user loads a maliciously crafted project file.

  • CVE-2025-7741LowMar 30, 2026
    risk 0.14cvss epss 0.00

    Hardcoded Password Vulnerability have been found in CENTUM. Affected products contain a hardcoded password for the user account (PROG) used for CENTUM Authentication Mode within the system. Under the following conditions, there is a risk that an attacker could log in as the…

  • CVE-2014-3888Jul 10, 2014
    risk 0.08cvss epss 0.62

    Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM VP R5.03.20 and earlier, Exaopc R3.72.00 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier, when FCS/Test Function is enabled,…

  • CVE-2014-0782May 16, 2014
    risk 0.08cvss epss 0.57

    Stack-based buffer overflow in BKESimmgr.exe in the Expanded Test Functions package in Yokogawa CENTUM CS 1000, CENTUM CS 3000 Entry Class R3.09.50 and earlier, CENTUM VP R5.03.00 and earlier, CENTUM VP Entry Class R5.03.00 and earlier, Exaopc R3.71.02 and earlier, B/M9000CS…

  • CVE-2014-0783Mar 14, 2014
    risk 0.08cvss epss 0.68

    Stack-based buffer overflow in BKHOdeq.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.

  • CVE-2014-0784Mar 14, 2014
    risk 0.06cvss epss 0.36

    Stack-based buffer overflow in BKBCopyD.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.

  • CVE-2014-5208Dec 22, 2014
    risk 0.05cvss epss 0.23

    BKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM VP through R4.03.00 and R5.x through R5.04.00, and Exaopc through R3.72.10, does not require authentication, which allows remote attackers to read arbitrary files via a RETR…

  • CVE-2014-0781Mar 14, 2014
    risk 0.05cvss epss 0.25

    Heap-based buffer overflow in BKCLogSvr.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via crafted UDP packets.

  • CVE-2014-7251Dec 6, 2014
    risk 0.00cvss epss 0.00

    XML external entity (XXE) vulnerability in the WebHMI server in Yokogawa Electric Corporation FAST/TOOLS before R9.05-SP2 allows local users to cause a denial of service (CPU or network traffic consumption) or read arbitrary files via unspecified vectors.

Page 2 of 2