PT-2014-2032 · Yokogawa · Yokogawa Centum Cs 3000

Publicado

2014-03-14

·

Atualizado

2025-09-25

·

CVE-2014-0781

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Yokogawa CENTUM CS 3000 versions R3.09.50 and earlier
Description The issue is related to a heap-based buffer overflow in the BKCLogSvr.exe service, which can be exploited by sending crafted UDP packets. This allows remote attackers to execute arbitrary code and potentially elevate their privileges. The vulnerability can be triggered by sending a specially crafted packet to port 52302/UDP.
Recommendations For Yokogawa CENTUM CS 3000 versions R3.09.50 and earlier, consider restricting access to the BKCLogSvr.exe service and port 52302/UDP to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Heap Based Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2021-05458
CVE-2014-0781

Produtos afetados

Yokogawa Centum Cs 3000