PT-2022-3578 · Yokogawa · Centum Vp Small+4

Published

2022-04-14

·

Updated

2022-04-22

·

CVE-2022-27188

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CENTUM VP versions R4.01.00 through R4.03.00 CENTUM VP Small versions R4.01.00 through R4.03.00 CENTUM VP Basic versions R4.01.00 through R4.03.00 B/M9000 VP versions R6.01.01 through R6.03.02
Description The issue exists due to the lack of measures to neutralize special elements used in the operating system command. This may allow an attacker who can access the computer where the affected product is installed to execute arbitrary OS commands by altering a file generated using Graphic Builder. The vulnerability in the Standard Operation and Monitoring function of distributed control systems may enable an attacker to execute arbitrary commands.
Recommendations For CENTUM VP versions R4.01.00 through R4.03.00, consider restricting access to the Graphic Builder feature until a patch is available. For CENTUM VP Small versions R4.01.00 through R4.03.00, consider restricting access to the Graphic Builder feature until a patch is available. For CENTUM VP Basic versions R4.01.00 through R4.03.00, consider restricting access to the Graphic Builder feature until a patch is available. For B/M9000 VP versions R6.01.01 through R6.03.02, consider restricting access to the Graphic Builder feature until a patch is available. As a temporary workaround, consider disabling the use of special elements in operating system commands to minimize the risk of exploitation.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04362
CVE-2022-27188

Affected Products

B/M9000 Vp
Centum Vp
Centum Vp Basic
Centum Vp Small
Graphic Builder