PT-2022-3911 · Yokogawa · Centum Vp Entry Class+4

Published

2022-07-29

·

Updated

2023-08-08

·

CVE-2022-33939

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions CENTUM VP / CS 3000 controller FCS (CP31, CP33, CP345, CP401, and CP451) CENTUM CS 3000 CENTUM CS 3000 Entry Class CENTUM VP CENTUM VP Entry Class
Description The issue is related to errors in resource management, which may lead to resource consumption. If exploited, an attacker may cause a denial of service (DoS) condition by sending specially crafted packets to the affected product. This can be achieved through ADL communication.
Recommendations For CENTUM VP / CS 3000 controller FCS (CP31, CP33, CP345, CP401, and CP451), consider restricting access to the communication packets processing module to minimize the risk of exploitation. For CENTUM CS 3000, CENTUM CS 3000 Entry Class, CENTUM VP, and CENTUM VP Entry Class, restrict access to the resource management module to prevent potential denial of service conditions. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2022-04724
CVE-2022-33939

Affected Products

Centum Cs 3000
Centum Cs 3000 Entry Class
Centum Vp
Centum Vp / Cs 3000 Controller Fcs
Centum Vp Entry Class