CAMS for HIS Log Server contained in the following Yokogawa Electric products is vulnerable to uncontrolled resource consumption. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00.
CAMS for HIS Log Server contenido en los siguientes productos de Yokogawa Electric es vulnerable al consumo no controlado de recursos. CENTUM CS 3000 versiones desde R3.08.10 a R3.09.00, CENTUM VP versiones desde R4.01.00 a R4.03.00, desde R5.01.00 a R5.04.20, desde R6.01.00 a R6.08.00, Exaopc versiones desde R3.72.00 a R3.79.00
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | NONE |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
AV:N/AC:M/Au:S/C:N/I:P/A:P
| Access Vector | NETWORK |
|---|---|
| Access Complexity | MEDIUM |
| Authentication | SINGLE |
| Confidentiality Impact | NONE |
| Integrity Impact | PARTIAL |
| Availability Impact | PARTIAL |
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-400
|
| [email protected] | Primary |
en
CWE-400
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| yokogawa | centum_cs_3000_firmware | * | <built-in method update of dict object at 0x7e6071e55840> | Operating System |
| yokogawa | centum_cs_3000_entry_firmware | * | <built-in method update of dict object at 0x7e6112c9ac00> | Operating System |
| yokogawa | centum_vp_firmware | * | <built-in method update of dict object at 0x7e60a8b7cbc0> | Operating System |
| yokogawa | centum_vp_firmware | * | <built-in method update of dict object at 0x7e6110cf6900> | Operating System |
| yokogawa | centum_vp_firmware | * | <built-in method update of dict object at 0x7e6071e54640> | Operating System |
| yokogawa | centum_vp_entry_firmware | * | <built-in method update of dict object at 0x7e6071e54a40> | Operating System |
| yokogawa | centum_vp_entry_firmware | * | <built-in method update of dict object at 0x7e61116aabc0> | Operating System |
| yokogawa | centum_vp_entry_firmware | * | <built-in method update of dict object at 0x7e61116a80c0> | Operating System |
| yokogawa | exaopc | * | <built-in method update of dict object at 0x7e60bac6f240> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:yokogawa:centum_cs_3000_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:yokogawa:centum_cs_3000:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:yokogawa:centum_cs_3000_entry_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:yokogawa:centum_cs_3000_entry:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:yokogawa:centum_vp_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:yokogawa:centum_vp_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:yokogawa:centum_vp_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:yokogawa:centum_vp:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:yokogawa:centum_vp_entry_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:yokogawa:centum_vp_entry_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:yokogawa:centum_vp_entry_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:yokogawa:centum_vp_entry:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:yokogawa:exaopc:*:*:*:*:*:*:*:* |