IM
IronMonkey Threat Research

CVE-2024-5650 HIGH

Published: 2024-06-17 | Last Modified: 2026-04-15 | Status: Deferred

Description

DLL Hijacking vulnerability has been found in CENTUM CAMS Log server provided by Yokogawa Electric Corporation. If an attacker is somehow able to intrude into a computer that installed affected product or access to a shared folder, by replacing the DLL file with a tampered one, it is possible to execute arbitrary programs with the authority of the SYSTEM account. The affected products and versions are as follows: CENTUM CS 3000 R3.08.10 to R3.09.50 CENTUM VP R4.01.00 to R4.03.00, R5.01.00 to R5.04.20, R6.01.00 to R6.11.10.

Additional Descriptions (1)

Se ha encontrado una vulnerabilidad de secuestro de DLL en CENTUM CAMS Log server provided by Yokogawa Electric Corporation. Si un atacante de alguna manera puede ingresar a una computadora que instaló el producto afectado o acceder a una carpeta compartida, reemplazando el archivo DLL por uno manipulado, es posible ejecutar programas arbitrarios con la autoridad de la cuenta de SYSTEM. Los productos y versiones afectados son los siguientes: CENTUM CS 3000 R3.08.10 a R3.09.50 CENTUM VP R4.01.00 a R4.03.00, R5.01.00 a R5.04.20, R6.01.00 a R6.11.10.

CVSS Metrics

Base Score: 8.5 (HIGH)

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack VectorNETWORK
Attack ComplexityHIGH
Privileges RequiredLOW
User InteractionNONE
ScopeCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: 7168b535-132a-4efe-a076-338f829b2eb9

Type: Secondary

Exploitability Score: 1.8

Impact Score: 6.0

Weaknesses

Source Type Description
7168b535-132a-4efe-a076-338f829b2eb9 Secondary
en CWE-284

References

Notification
Message here