IM
IronMonkey Threat Research
‹ Back to ICS Advisories

YSAR-22-0004: Vulnerabilities in CENTUM and ProSafe-RS

HIGH
CVSS 7.5
Date 2026-07-28T15:26:50+00:00
Source yokogawa
Published by Yokogawa

// Description

1 / 3YSAR-22-0004-E Yokogawa Security Advisory Report > All Rights Reserved. Copyright © 2022, Yokogawa Electric Corporation # Yokogawa Security Advisory Report # YSAR-22-0004 Published on March 10, 2022 Last updated on April 26, 2022 ## YSAR-22-0004: Vulnerabilities in CENTUM and ProSafe-RS Overview: Vulnerabilities have been found in CENTUM and ProSafe-RS. Yokogawa has identified the range of affected products in this report. Review the report and confirm which products are

// Vulnerabilities (5)

CVE ID CVSS Score Severity Description
CVE-2022-27188 7.5 high
A local attacker could tamper with files generated by the graphic builder, which may allow arbitrary programs to be executed on a computer that has installed standard operation and monitoring function (HIS).CVE-2022-27188 has been assigned to this vulnerability. A CVSS v3 base score of 6.1 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H).
CVE-2018-11782 7.5 high
The AD suite version management function is subjected to malformed packets, which the functions provided by the AD server may stop.CVE-2018-11782 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2022-26034 7.5 high
Improper authentication of the communication protocol provided by the Automation Design (AD) server allows an attacker to use the functions provided by the AD server. This may lead to leakage or tampering of data managed by the AD server.CVE-2022-26034 has been assigned to this vulnerability. A CVSS v3 base score of 6.4 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L).
CVE-2019-0203 7.5 high
The AD suite version management function is subjected to malformed packets, which the functions provided by the AD server may stop.CVE-2019-0203 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2015-0248 7.5 high
The AD suite version management function is subjected to malformed packets, which the functions provided by the AD server may stop.CVE-2015-0248 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

// Affected Products (2)

Vendor Product Asset Type Purdue Level Firmware
Yokogawa Unknown dcs
L2
--
Yokogawa Unknown safety_system
L1
--

// Remediations (9)

Mitigation: For more information see Yokogawa security advisory report: YSAR-22-0004
For more information see Yokogawa security advisory report: YSAR-22-0004
Mitigation: B/M9000 VP: This product is not affected by these vulnerabilities. However, this product is affected
B/M9000 VP: This product is not affected by these vulnerabilities. However, this product is affected by the existence of CENTUM installed on the same PC. If CENTUM is installed, perform update, and update B/M9000 to suitable revision.
Mitigation: Contact Yokogawa support for more mitigation information.
Contact Yokogawa support for more mitigation information.
Patch: Users of Prosafe-RS: Update to R4.07.02 or later
Users of Prosafe-RS: Update to R4.07.02 or later
Mitigation: Users of CENTUM Versions R4.01.00 though R4.03.00: No patch software will be available because these
Users of CENTUM Versions R4.01.00 though R4.03.00: No patch software will be available because these products are no longer supported by the vendor.
Mitigation: The environment where both CENTUM VP and ProSafe-RS are installed.
The environment where both CENTUM VP and ProSafe-RS are installed.
Mitigation: Users of CENTUM Versions R6.01.10 through R6.09.00: Update to R6.09.00 and apply patch software (R6.
Users of CENTUM Versions R6.01.10 through R6.09.00: Update to R6.09.00 and apply patch software (R6.09.04). In an environment where the AD server and Plant Resource Manager (PRM) are linked, there are some precautions to be taken when applying patch software (R6.09.04). Please be sure to check R6.09.04 install manual for details before applying R6.09.04
Mitigation: The environment where CENTUM VP's AD server and PRM are linked.
The environment where CENTUM VP's AD server and PRM are linked.
Mitigation: The environment where ProSafe-RS's AD server and PRM are linked.
The environment where ProSafe-RS's AD server and PRM are linked.

// References