IM
IronMonkey Threat Research
‹ Back to ICS Advisories

YSAR-20-0001

HIGH
CVSS 8.1
Date 2026-07-28T15:27:16+00:00
Source yokogawa
Published by Yokogawa

// Description

1 / 3YSAR-20-0001-E Yokogawa Security Advisory Report > All Rights Reserved. Copyright © 2020, Yokogawa Electric Corporation # Yokogawa Security Advisory Report # YSAR-20-0001 Published on July 31, 2020 Last updated on December 2, 2020 ## YSAR-20-0001: Vulnerabilities in CAMS for HIS Overview: Vulnerabilities have been found in CAMS for HIS of CENTUM. Yokogawa has identified the range of affected products in this report. Review the report and confirm which products are affected to i

// Vulnerabilities (2)

CVE ID CVSS Score Severity Description
CVE-2020-5608 8.1 high
This vulnerability may allow a remote unauthenticated attacker to send tampered communication packets.CVE-2020-5608 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).
CVE-2020-5609 8.1 high
This vulnerability may allow a remote attacker to create or overwrite any file, run any commands.CVE-2020-5609 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).

// Affected Products (2)

Vendor Product Asset Type Purdue Level Firmware
Yokogawa Unknown dcs
L2
--
Yokogawa Unknown dcs
L2
--

// Remediations (7)

Mitigation: More details can also be found in Yokogawa's security advisory report number YSAR-20-0001
More details can also be found in Yokogawa's security advisory report number YSAR-20-0001
Mitigation: For questions related to this report, please contact Yokogawa support.
For questions related to this report, please contact Yokogawa support.
Mitigation: Exaopc R3.72.00 - R3.78.00: Update to R3.78.10 or later.
Exaopc R3.72.00 - R3.78.00: Update to R3.78.10 or later.
Mitigation: For CENTUM VP (including CENTUM VP Entry Class) R5.01.00 - R5.04.20, apply patch R5.04.D1
For CENTUM VP (including CENTUM VP Entry Class) R5.01.00 - R5.04.20, apply patch R5.04.D1
Mitigation: For CENTUM VP (including CENTUM VP Entry Class) R6.01.00 - R6.07.00, apply patch R6.07.11
For CENTUM VP (including CENTUM VP Entry Class) R6.01.00 - R6.07.00, apply patch R6.07.11
Mitigation: For CENTUM CS 3000 (including CENTUM CS 3000 Entry Class) R3.08.10 - R3.09.50 and CENTUM VP (includi
For CENTUM CS 3000 (including CENTUM CS 3000 Entry Class) R3.08.10 - R3.09.50 and CENTUM VP (including CENTUM VP Entry Class) R4.01.00 - R4.03.00, no patch will be available because these products are already end of support. Yokogawa recommends that affected customers upgrade to the latest revision of CENTUM VP.
Patch: For B/M9000CS R5.04.01 - R5.05.01 and B/M9000 VP R6.01.01 - R8.03.01, Yokogawa reports that this pro
For B/M9000CS R5.04.01 - R5.05.01 and B/M9000 VP R6.01.01 - R8.03.01, Yokogawa reports that this product is not affected by the vulnerabilities but is affected by the existence of CENTUM CS 3000 installed on the same PC. If CENTUM CS 3000 is installed, update B/M90000CS to suitable revision. If CENTUM VP is installed on the same PC, update to B/M90000 VP to suitable revision.

// References