PT-2022-3911 · Yokogawa · Centum Vp Entry Class+4
Published
2022-07-29
·
Updated
2023-08-08
·
CVE-2022-33939
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
CENTUM VP / CS 3000 controller FCS (CP31, CP33, CP345, CP401, and CP451)
CENTUM CS 3000
CENTUM CS 3000 Entry Class
CENTUM VP
CENTUM VP Entry Class
Description
The issue is related to errors in resource management, which may lead to resource consumption. If exploited, an attacker may cause a denial of service (DoS) condition by sending specially crafted packets to the affected product. This can be achieved through ADL communication.
Recommendations
For CENTUM VP / CS 3000 controller FCS (CP31, CP33, CP345, CP401, and CP451), consider restricting access to the communication packets processing module to minimize the risk of exploitation.
For CENTUM CS 3000, CENTUM CS 3000 Entry Class, CENTUM VP, and CENTUM VP Entry Class, restrict access to the resource management module to prevent potential denial of service conditions.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Centum Cs 3000
Centum Cs 3000 Entry Class
Centum Vp
Centum Vp / Cs 3000 Controller Fcs
Centum Vp Entry Class