PT-2020-3924 · Yokogawa · Cams For His B/M9000 Vp+3
Ivan Kurnakov
+1
·
Published
2020-07-31
·
Updated
2020-08-12
·
CVE-2020-5609
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
CAMS for HIS CENTUM CS 3000 versions R3.08.10 through R3.09.50
CAMS for HIS CENTUM VP versions R4.01.00 through R6.07.00
CAMS for HIS B/M9000CS versions R5.04.01 through R5.05.01
CAMS for HIS B/M9000 VP versions R6.01.01 through R8.03.01
Description:
The issue is related to a directory traversal vulnerability in the CAMS for HIS component, which is associated with inadequate path name checking. This allows a remote unauthenticated attacker to create or overwrite arbitrary files and run arbitrary commands via unspecified vectors.
Recommendations:
For CAMS for HIS CENTUM CS 3000 versions R3.08.10 through R3.09.50, update to a version outside of this range to resolve the issue.
For CAMS for HIS CENTUM VP versions R4.01.00 through R6.07.00, update to a version outside of this range to resolve the issue.
For CAMS for HIS B/M9000CS versions R5.04.01 through R5.05.01, update to a version outside of this range to resolve the issue.
For CAMS for HIS B/M9000 VP versions R6.01.01 through R8.03.01, update to a version outside of this range to resolve the issue.
As a temporary workaround, consider restricting access to the CAMS for HIS component to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cams For His B/M9000 Vp
Cams For His B/M9000Cs
Cams For His Centum Cs 3000
Cams For His Centum Vp