IM
IronMonkey Threat Research

CVE-2022-33939 HIGH

Published: 2022-08-16 | Last Modified: 2024-11-21 | Status: Modified

Description

CENTUM VP / CS 3000 controller FCS (CP31, CP33, CP345, CP401, and CP451) contains an issue in processing communication packets, which may lead to resource consumption. If this vulnerability is exploited, an attacker may cause a denial of service (DoS) condition in ADL communication by sending a specially crafted packet to the affected product.

Additional Descriptions (1)

El controlador CENTUM VP / CS 3000 FCS (CP31, CP33, CP345, CP401 y CP451) contiene un problema en el procesamiento de paquetes de comunicación, que puede conllevar a un consumo de recursos. Si es aprovechada esta vulnerabilidad, un atacante puede causar una condición de denegación de servicio (DoS) en la comunicación ADL mediante el envío de un paquete especialmente diseñado al producto afectado.

CVSS Metrics

Base Score: 7.5 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 3.6

Weaknesses

Source Type Description
[email protected] Primary
en NVD-CWE-noinfo

Affected Products

Vendor Product Version Update Type
yokogawa centum_cs_3000_cp401_firmware - <built-in method update of dict object at 0x7e60e832e340> Operating System
yokogawa centum_cs_3000_cp451_firmware - <built-in method update of dict object at 0x7e60a8a54880> Operating System
yokogawa centum_cs_3000_cp33_firmware - <built-in method update of dict object at 0x7e60bafacd40> Operating System
yokogawa centum_cs_3000_cp345_firmware - <built-in method update of dict object at 0x7e60a8ba9080> Operating System
yokogawa centum_cs_3000_cp31_firmware - <built-in method update of dict object at 0x7e60e832d7c0> Operating System
yokogawa centum_vp_3000_cp401_firmware * <built-in method update of dict object at 0x7e60e832fcc0> Operating System
yokogawa centum_vp_3000_cp401_firmware * <built-in method update of dict object at 0x7e60bafacf80> Operating System
yokogawa centum_vp_3000_cp401_firmware * <built-in method update of dict object at 0x7e60a8babc00> Operating System
yokogawa centum_vp_3000_cp451_firmware * <built-in method update of dict object at 0x7e60bafac480> Operating System
yokogawa centum_vp_3000_cp451_firmware * <built-in method update of dict object at 0x7e60e832e400> Operating System
yokogawa centum_vp_3000_cp451_firmware * <built-in method update of dict object at 0x7e6071ebb780> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:yokogawa:centum_cs_3000_cp401_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:yokogawa:centum_cs_3000_cp401:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:yokogawa:centum_cs_3000_cp451_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:yokogawa:centum_cs_3000_cp451:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:yokogawa:centum_cs_3000_cp33_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:yokogawa:centum_cs_3000_cp33:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:yokogawa:centum_cs_3000_cp345_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:yokogawa:centum_cs_3000_cp345:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:yokogawa:centum_cs_3000_cp31_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:yokogawa:centum_cs_3000_cp31:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:yokogawa:centum_vp_3000_cp401_firmware:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:yokogawa:centum_vp_3000_cp401_firmware:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:yokogawa:centum_vp_3000_cp401_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:yokogawa:centum_vp_3000_cp401:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:yokogawa:centum_vp_3000_cp451_firmware:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:yokogawa:centum_vp_3000_cp451_firmware:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:yokogawa:centum_vp_3000_cp451_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:yokogawa:centum_vp_3000_cp451:-:*:*:*:*:*:*:*
Notification
Message here