Improper Authentication in AD Server of CENTUM VP and B/M9000 Products
CVE-2022-26034
9.1CRITICAL
Key Information:
- Vendor
- CVE Published:
- 15 April 2022
Summary
The improper authentication vulnerability in the AD (Automation Design) server used in Yokogawa's CENTUM VP series and B/M9000 VP products allows unauthorized access to critical functions. This can result in unauthorized manipulation of data or its unauthorized exposure. Attackers exploiting this vulnerability may significantly impact operations by enabling data leakage or tampering with the data managed by the AD server.
Affected Version(s)
CENTUM VP series with VP6E5000(AD Suite Engineering ServerFunction) installed and B/M9000 VP CENTUM VP R6.01.10 to R6.09.00, CENTUM VP Small R6.01.10 to R6.09.00, CENTUM VP Basic R6.01.10 to R6.09.00, and B/M9000 VP R8.01.01 to R8.03.01
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved