PT-2018-3763 · Yokogawa · Centum Vp Small+8

Published

2018-04-17

·

Updated

2020-10-02

·

CVE-2018-8838

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CENTUM CS 1000 all versions CENTUM CS 3000 versions R3.09.50 and earlier CENTUM CS 3000 Small versions R3.09.50 and earlier CENTUM VP versions R6.03.10 and earlier CENTUM VP Small versions R6.03.10 and earlier CENTUM VP Basic versions R6.03.10 and earlier Exaopc versions R3.75.00 and earlier B/M9000 CS all versions B/M9000 VP versions R8.01.01 and earlier
Description A weakness in access controls may allow a local attacker to exploit the message management function of the system. This could potentially enable an attacker to generate false system or technological alarm signals or block alarm signals.
Recommendations For CENTUM CS 1000, consider restricting access to the message management function until a patch is available. For CENTUM CS 3000 versions R3.09.50 and earlier, update to a version later than R3.09.50. For CENTUM CS 3000 Small versions R3.09.50 and earlier, update to a version later than R3.09.50. For CENTUM VP versions R6.03.10 and earlier, update to a version later than R6.03.10. For CENTUM VP Small versions R6.03.10 and earlier, update to a version later than R6.03.10. For CENTUM VP Basic versions R6.03.10 and earlier, update to a version later than R6.03.10. For Exaopc versions R3.75.00 and earlier, update to a version later than R3.75.00. For B/M9000 CS, restrict access to the system until a patch is available. For B/M9000 VP versions R8.01.01 and earlier, update to a version later than R8.01.01.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05461
CVE-2018-8838

Affected Products

B/M9000Cs
B/M9000 Vp
Centum Cs 1000
Centum Cs 3000
Centum Cs 3000 Small
Centum Vp
Centum Vp Basic
Centum Vp Small
Exaopc