Improper ACL Configuration in Yokogawa Electric's Long-term Data Archive Package
CVE-2022-22141

7.8HIGH

Key Information:

Vendor
CVE Published:
11 March 2022

Summary

The Long-term Data Archive Package service provided by Yokogawa Electric exhibits a vulnerability due to improper ACL configurations on named pipes. This misconfiguration can potentially allow unauthorized access to sensitive data and systems within the affected versions of CENTUM CS 3000, CENTUM VP, and Exaopc products. Organizations utilizing these versions should review their security protocols and apply the necessary patches to mitigate risks associated with this vulnerability.

Affected Version(s)

CENTUM CS 3000 versions from R3.08.10 to R3.09.00

CENTUM VP versions from R4.01.00 to R4.03.00

CENTUM VP versions from R5.01.00 to R5.04.20

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.