OS Command Injection Vulnerability in Yokogawa CENTUM VP and B/M9000 VP Products
CVE-2022-27188
7.8HIGH
Key Information:
- Vendor
- CVE Published:
- 15 April 2022
Summary
An OS command injection vulnerability exists in various versions of Yokogawa's CENTUM VP and B/M9000 VP products. This flaw allows an attacker with access to the installation environment to execute arbitrary operating system commands by manipulating a file generated via the Graphic Builder tool. If exploited, this may lead to unauthorized access or control over the affected system.
Affected Version(s)
CENTUM VP series with VP6E5150(Graphic Builder) installed and B/M9000 VP CENTUM VP R4.01.00 to R4.03.00, CENTUM VP Small R4.01.00 to R4.03.00, CENTUM VP Basic R4.01.00 to R4.03.00, and B/M9000 VP R6.01.01 to R6.03.02
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved